Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5ba14c04937e8f6…

MALICIOUS

PDF

78.1 KB Created: 2021-04-07 00:56:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e8c54be6ecac88b2912aaf63cda6e93e SHA-1: b14903b677c16ece62bbdbe0f9552d3e2d4aa831 SHA-256: e5ba14c04937e8f6319cb6509e4c1b5eb622bd5884ccc87dc1df1ac45ee3f244
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL, https://resalured.ru/123?utm_term=1040x+amended+tax+form+2016, which is likely the primary vector for the attack. The document body, though heavily obfuscated, suggests a lure related to tax forms, aligning with common phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/123?utm_term=1040x+amended+tax+form+2016
    • https://static.s123-cdn-static.com/uploads/4489237/normal_5fcf5852576cc.pdf
    • https://cdn-cms.f-static.net/uploads/4383444/normal_601a4ac0018c7.pdf
    • https://cdn-cms.f-static.net/uploads/4422627/normal_60608ef88b626.pdf
    • http://golesaluwo.66ghz.com/pdf_auditing_standards.pdf
    • http://mon-cmso.best/free_printable_synonym_worksheets_for_5th_gradecz6lv.pdf
    • https://cdn-cms.f-static.net/uploads/4376599/normal_602de2c810de7.pdf
    • http://esparks.ru/does_gamestop_fix_nintendo_dswfc5z.pdf
    • http://wuwulobuxalajut.iblogger.org/43219509360.pdf
    • http://belplitka.ru/highway_to_heaven_song_lyrics_nctf9hsl.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/bd216ddf-609e-45bc-a658-3994d458f928/washington_dc_covid_19_vaccine_sign_up.pdf
    • https://uploads.strikinglycdn.com/files/dc3ec7e2-5694-4c8a-91b3-e2d18a29a794/dezenaxo.pdf
    • https://uploads.strikinglycdn.com/files/d4d83928-0d00-435a-9730-a0ff237145ca/begeleg.pdf
    • https://s3.amazonaws.com/gelawiweza/35533344738.pdf
    • https://uploads.strikinglycdn.com/files/371bb0af-6c11-4dc5-978f-057011fb8acc/leposatamidaniso.pdf
    • https://uploads.strikinglycdn.com/files/82828b56-370a-4ec5-8649-534f47aeaab0/rivorakobujifiv.pdf
    • https://uploads.strikinglycdn.com/files/77408272-d240-4910-a254-9c07ed37bea3/84529823904.pdf
    • https://uploads.strikinglycdn.com/files/2101f025-d548-4b8f-b6cd-c5b04721c51b/93215765602.pdf
    • https://uploads.strikinglycdn.com/files/62d4d650-9255-4f36-ba8d-2c2e6eb9c79f/2105156998.pdf
    • https://uploads.strikinglycdn.com/files/5244acbc-ab45-4baa-bb37-e7dc81986f2e/garmin_94sv_plus_livescope.pdf
    • https://s3.amazonaws.com/netinuwa/the_most_dangerous_game_question_support_answers.pdf
    • http://zalowakudedakov.rf.gd/yasin_suresi_latince.pdf
    • https://s3.amazonaws.com/dejolavubukugeb/8146624657.pdf
    • https://s3.amazonaws.com/pusori/ruduwutikokanugazo.pdf
    • https://s3.amazonaws.com/gagotaniwipure/rudonoronafapafi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e6d8.bin
d28ae7ba77208c83c935f7efca4a069d74d18ede71be6bea51cdab9340a5517e
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6D8 5124 bytes
font_01_sfnt_off0000f824.bin
1e72bca6ed667fc793262f6ce44681e7c838fa1baf9293e5e63df9e1acf393ef
pdf-font-stream PDF embedded font (sfnt) at offset 0xF824 10608 bytes
font_02_sfnt_off00011c87.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C87 4324 bytes