Malicious PDF — malware analysis report

Static analysis result for SHA-256 f43aa79e7f2d5f44…

MALICIOUS

PDF

76.7 KB Created: 2021-04-11 03:09:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 582f6e8ecca1e062a062ab457b86a6a9 SHA-1: 592a197bc1e8e6be511ece1f5ba733009a83d0a6 SHA-256: f43aa79e7f2d5f4461961d92c235626cd6c0256492a50370ae87b4ede5605796
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and ML classifiers indicated a high probability of maliciousness. It contains a large number of external links, many of which are to PDF files, suggesting a link farm or redirection mechanism. One of the primary external URIs, 'https://resalured.ru/strik?utm_term=what+foods+constitute+an+alkaline+diet', is likely part of a phishing or malware distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=what+foods+constitute+an+alkaline+diet
    • http://d2-club.ru/how_do_you_turn_on_a_microsoft_wireless_keyboard_200037omm.pdf
    • http://leoidet.xyz/24995322028rmbru.pdf
    • http://optamorem.com/construction_site_visit_report_exampleypwwj.pdf
    • https://risibazizugati.weebly.com/uploads/1/3/4/7/134710005/paroboxex.pdf
    • https://bejizasidofivi.weebly.com/uploads/1/3/4/2/134234705/nativolipa.pdf
    • https://kimimidinom.weebly.com/uploads/1/3/1/4/131453749/vukatorolesi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://587b455d-cc79-4428-8e80-a8b75ce23bca.filesusr.com/ugd/021ec8_da13293fcdf2446db1b459e2be5615ff.pdf?index=true
    • https://37523d11-79cf-4eb3-ada4-f05de57c71ee.filesusr.com/ugd/275374_68f3a984223b47beaa4bb0b17ef5f393.pdf?index=true
    • https://s3.amazonaws.com/kewuxejikiwe/fallen_order_star_wars_timeline.pdf
    • https://204833c8-abda-4421-8777-5048ee7dd919.filesusr.com/ugd/e30b7a_fff216f5f0594f61bb6f44e3335fc16f.pdf?index=true
    • https://d62ff7d9-aefc-4ab8-8cdf-af38868aea16.filesusr.com/ugd/54b9a1_f3ea2230c863475ea68630bf21f0b0bb.pdf?index=true
    • https://s3.amazonaws.com/jixeremipet/zolaragedurawurekodusufiw.pdf
    • https://s3.amazonaws.com/marimejerebo/84522901099.pdf
    • https://2c549fd3-bbcc-4e43-aea5-84609313cfd4.filesusr.com/ugd/c162b3_97dd8e09f83e4c538c47125fd6aab121.pdf?index=true
    • https://s3.amazonaws.com/farefasejikap/coleman_spa_pump_heater.pdf
    • https://711a90e7-97f2-4eab-8690-3003ec1e9b64.filesusr.com/ugd/a0905b_44d6775082314e33a511fcdee7255ade.pdf?index=true
    • https://s3.amazonaws.com/tixedujegibex/bosch_silence_plus_44_dba_loading_instructions.pdf
    • https://s3.amazonaws.com/sebunuzu/43729563543.pdf
    • https://26f2e344-8444-46ea-90c9-5a893bcc2fb3.filesusr.com/ugd/b8c837_aa8386e73bce4dc48a54e76a0899c3d8.pdf?index=true
    • https://ca6b24e6-01cd-4368-a310-1df05077a315.filesusr.com/ugd/11b39a_6f505a3049c44d0fb48748408ff6c484.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f138.bin
54d97853d3a4713120f7eb06f867c9ed091f791f9264e8cf69485372329c89b7
pdf-font-stream PDF embedded font (sfnt) at offset 0xF138 5092 bytes
font_01_sfnt_off0001029d.bin
7abd1a8b72479011db8d6117d1945867cd0a1fbde9378273b6c4399858897200
pdf-font-stream PDF embedded font (sfnt) at offset 0x1029D 10288 bytes