Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcb03e0d3d8cb426…

MALICIOUS

PDF

134.3 KB Created: 2021-04-05 06:19:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-04
MD5: feea26483249004592ff965330d010ff SHA-1: 5f793555460e5be815287a79ca940e0854ee40cc SHA-256: dcb03e0d3d8cb426d3c53a7c5cad4a90d96df1123152a8ffa79a0a2fef30c27d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan' and an ML classifier indicating high maliciousness. The PDF contains a large number of external links, with one pointing to 'https://resalured.ru/123?utm_term=ihya+al+ghazali+pdf', suggesting a link farm or phishing attempt. While no scripts were explicitly extracted, the presence of numerous external links and the overall detection profile strongly indicate malicious intent, likely to redirect users to a compromised site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/123?utm_term=ihya+al+ghazali+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4472221/normal_6033da80310ac.pdfIn PDF document text
    • http://nalodorepuwag.getenjoyment.net/wufipamodusureg.pdfIn PDF document text
    • http://lololoj.sportsontheweb.net/what_does_woe_mean_in_keto_diet.pdfIn PDF document text
    • http://nijaxubazaziw.mypressonline.com/malikawenusuwonivino.pdfIn PDF document text
    • http://gixodugesu.medianewsonline.com/mario_vargas_llosa_libros_gratis.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417643/normal_6025b9955119c.pdfIn PDF document text
    • http://tuvosudokalidu.scienceontheweb.net/divejivivip.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/fulosobezur/figurative_speech_worksheets_with_answers.pdfIn PDF document text
    • https://6e678f60-abc6-404c-883a-cd1729fdffee.filesusr.com/ugd/e4291f_d2504d0c973e41c9804320eea9fe98c1.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/moduluzuxikari/apr_performance_mustang_front_wind_splitter.pdfIn PDF document text
    • https://3064a0a7-8496-4b95-be1e-56094aee372f.filesusr.com/ugd/0cf4b9_f027d73eb2a445919a6ae9da642fd104.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/debiwelof/what_is_the_cheapest_70_inch_tv.pdfIn PDF document text
    • https://s3.amazonaws.com/setigafat/33640746694.pdfIn PDF document text
    • https://s3.amazonaws.com/sinamozagemoger/ritanejupesawexelozalofe.pdfIn PDF document text
    • http://ralirajuz.atwebpages.com/15157886625.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/97b379b9-d67f-4af5-b4b8-139277d696e9/how_do_you_use_urpower_essential_oil_diffuser.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/924aaaf2-d6f0-4591-a788-bf3f0178fd61/14401484732.pdfIn PDF document text
    • https://8d94caac-80d5-4f6d-a73a-04ed47837dc1.filesusr.com/ugd/585b1d_3e1d27ae304d41e4be7e337c4a0faca0.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0001e80a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1E80A 21212 bytes
SHA-256: 8696eb8128e97bfd95765eb61c4bf20eec3a6d233f8e9c5fdc682c4f56ff6c86
font_00_sfnt_off0001a9d4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1A9D4 5116 bytes
SHA-256: ddf11ef24a696d2751b25529e7b91bd69121ae2033b0158f870786cc820603da
font_01_sfnt_off0001bb53.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1BB53 14436 bytes
SHA-256: 653221a89916d0cd3bc7aa3db0261cf2e81d1de66ecf3d9278514c4af9e63b14