Malicious PDF — malware analysis report

Static analysis result for SHA-256 a43b4c4ae94c3d91…

MALICIOUS

PDF

86.8 KB Created: 2021-03-13 16:20:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9148808a133e39b2bd012af74425c1b5 SHA-1: 49b62500da26f5a9c27672ea9da83dc5ea758416 SHA-256: a43b4c4ae94c3d914aa992383af678bed65691332fc83454ee6b90e7d6ff7ebb
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV and an ML classifier as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'resalured.ru', which is likely part of a phishing or malware distribution scheme. Although no scripts were directly extracted, the PDF structure and embedded URI suggest an attempt to trick the user into downloading further malicious content, aligning with a spearphishing attachment attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=kicad+manual+espa%25C3%25B1ol
    • http://christinaanddavid2019.com/xinojunasusobirisupugim8zth.pdf
    • https://cdn-cms.f-static.net/uploads/4449793/normal_601f63e994236.pdf
    • https://wakezibi.weebly.com/uploads/1/3/4/6/134695128/f6c0fe4e7352d.pdf
    • https://ruwagifixub.weebly.com/uploads/1/3/4/0/134013037/c03c1c4f4a1477.pdf
    • https://webemimerur.weebly.com/uploads/1/3/1/3/131380848/7002777.pdf
    • https://cdn-cms.f-static.net/uploads/4469378/normal_6025bda760224.pdf
    • https://cdn-cms.f-static.net/uploads/4459170/normal_5fd09ef970f60.pdf
    • http://sait-ok.ru/ocdsb_report_card_login3qzh8.pdf
    • http://chambrehub.xyz/32969465134794qc.pdf
    • http://mnogoturov.com/terraria_1.3.5.3_all_items_map_download8qtej.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zowujobosega.rf.gd/dean_koontz_jane_hawk_series_book_6.pdf
    • https://s3.amazonaws.com/zozuxukoxo/mitsubishi_mr_slim_1_ton_ac_price_in_pakistan.pdf
    • https://s3.amazonaws.com/bomupi/8472293560.pdf
    • http://supikatiwo.rf.gd/ledumosididekedemegikik.pdf
    • http://bafajomagiguva.rf.gd/jibetosaradizovinuje.pdf
    • https://s3.amazonaws.com/fezenur/attentat_1942_hra.pdf
    • https://e22e8d81-f41f-4d51-abb1-39b19d2d32bb.filesusr.com/ugd/96bf9d_2759c64a2c2f411b8d001a037681dc5f.pdf?index=true
    • https://535a9070-e28a-464b-adc5-c02ad08be00b.filesusr.com/ugd/9df9d6_344b2d4358854f268564834c53b8a301.pdf?index=true
    • https://s3.amazonaws.com/dezajok/zolevib.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea2d.bin
9a45bd46f43b0b87c5a0d6bd54f82c5f3be0d82372e3eb313d451ac7df0c2eb9
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA2D 6004 bytes
font_01_sfnt_off0000fe49.bin
156088dca14eed5336da821615275d51ff56067e39869bf541870b656ada02b0
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE49 5304 bytes
font_02_sfnt_off0001100c.bin
866d2f435d5531b99fe00b3f8150b675f1613101aa91345ddebc9962ecb79b11
pdf-font-stream PDF embedded font (sfnt) at offset 0x1100C 11380 bytes
font_03_sfnt_off000136d4.bin
b91ebbfc40a94f10b2fcfc4d08542e4cd4fc38dcff43bcfefe5d572695fcce17
pdf-font-stream PDF embedded font (sfnt) at offset 0x136D4 16160 bytes