Malicious PDF — malware analysis report

Static analysis result for SHA-256 98ce040421f9655e…

MALICIOUS

PDF

68.3 KB Created: 2021-03-03 14:43:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6d29a677a1bfdbf5384441fe2e15afe8 SHA-1: d65a4cc32772fe5eea44ea4e4f68e638c898344d SHA-256: 98ce040421f9655e8902fdcf9675b7377419901883e51c3b2345ed5a646fd271
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with heuristics indicating the presence of external URIs and embedded URLs. The document body, though heavily obfuscated, contains strings that suggest a lure related to 'Nyssma sight singing examples'. The primary malicious URL identified is https://resalured.ru/strik. The PDF structure and embedded content point towards a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=nyssma+sight+singing+examples
    • http://metoxegid.mygamesonline.org/how_to_access_asus_router_configuration.pdf
    • https://cdn.sqhk.co/gebemiwisero/jcgp1jf/tarex.pdf
    • https://cdn-cms.f-static.net/uploads/4446374/normal_603c3ebbaf070.pdf
    • https://cdn.sqhk.co/zukuxenopo/ghGIBrb/tagabiteweniwi.pdf
    • https://cdn.sqhk.co/dugixikisim/7UgckMj/motor_touring_250cc_murah.pdf
    • https://cdn.sqhk.co/buzaxelubot/ggohfgc/top_hits_70_80_90.pdf
    • https://cdn-cms.f-static.net/uploads/4372960/normal_600e3247d25c1.pdf
    • https://cdn.sqhk.co/kujotukil/pOiii4h/gravity_payments_stock.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/paxuvagal/89574717487.pdf
    • https://s3.amazonaws.com/fumiposamisur/sengoku_basara_ppsspp_ukuran_kecil.pdf
    • https://s3.amazonaws.com/simujix/32956728135.pdf
    • http://kedisijusa.onlinewebshop.net/vifomo.pdf
    • https://s3.amazonaws.com/petuzutemixuvod/kikib.pdf
    • https://s3.amazonaws.com/gotijejaj/14835600202.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d002.bin
84b0a34b0c9eecbf0e2da5064fde557f102fa22cd7e35ec7b0eb6dc8e40e0ddc
pdf-font-stream PDF embedded font (sfnt) at offset 0xD002 5276 bytes
font_01_sfnt_off0000e1e6.bin
58d7125a7b65551d2a5f342d2dc2877244afa46f5c75e39ab925616304febf8c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE1E6 10100 bytes