Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff000e7f90ce595d…

MALICIOUS

PDF

81.4 KB Created: 2021-03-25 17:36:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e83572bc4789bd109c8c1be7dc29a5aa SHA-1: 7dbcffbaf723cdcb4bf980ede42f0e3e97feec81 SHA-256: ff000e7f90ce595d9f2deba2aaaec5c80dbce4cd4bc25b8afa574b7538aafe41
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by ML classifiers and ClamAV as malicious. It contains an embedded URI pointing to a suspicious domain, 'resalured.ru', which is likely used to host phishing content or a secondary payload. The document body is heavily obfuscated, but the presence of the external URI suggests an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=highwaymen+parents+guide
    • http://meetraisins.club/levupadal7v.pdf
    • http://dotekebenutedex.scienceontheweb.net/seismic_tomography_theory_and_practice.pdf
    • http://futajef.medianewsonline.com/how_to_quit_drinking_without_aa_book.pdf
    • http://winsbig.space/9742317463678m8f.pdf
    • http://gagivukamuw.getenjoyment.net/tadojurujudalidoruluv.pdf
    • http://presente-top.store/netgear_ac1600_r6250_manual786m4.pdf
    • http://smallita.space/pigalisadepedotubrzf9.pdf
    • http://miribut.mywebcommunity.org/janiwolomug.pdf
    • http://domotoj.sportsontheweb.net/firuwerabezetivifawigom.pdf
    • http://ouily.xyz/58326135740059d1.pdf
    • http://tokio-2020.fun/wosomop93f81.pdf
    • http://interbankdigital.com/how_to_make_an_end_fed_wire_antennarufq5.pdf
    • http://xolululumaw.iblogger.org/68494627755.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://latujetob.epizy.com/46681535605.pdf
    • http://dufobirufo.atwebpages.com/assured_shorthold_tenancy_agreement_nla.pdf
    • http://kibisabekod.rf.gd/bevevu.pdf
    • http://pedamodaw.onlinewebshop.net/how_to_adjust_rainbird_5000_sprinkler_head_distance.pdf
    • https://7f03322d-63d6-449b-a8c2-a80beffeb2b6.filesusr.com/ugd/2994dd_98f78d885a5243a48aaadbbf9f57ecb0.pdf?index=true
    • https://7a6021ad-ea99-40b3-bafb-6570e045b460.filesusr.com/ugd/527ec5_4b00c75525ce4612a1efd7a153799893.pdf?index=true
    • http://dupepoge.onlinewebshop.net/sunbeam_heated_blanket_microplush_10_heat_settings_garnet_full.pdf
    • http://noxofovamoz.epizy.com/darwin_voyage_of_the_beagle.pdf
    • https://9e1b5e4e-b4ab-405b-8fdf-b3b6d7b19c28.filesusr.com/ugd/94ea38_f800737faa544e8198dfb32dbb856fc6.pdf?index=true
    • https://48e6b720-b653-4920-beb0-7ef171ab6ab9.filesusr.com/ugd/d9d1f5_7a5289607cbc425891fab2b4e7f47f2b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f33a.bin
0ea7f79a1e65a138f9cbc74e5bde86f0383ad565160d1fe9bc7263591e5359ca
pdf-font-stream PDF embedded font (sfnt) at offset 0xF33A 5268 bytes
font_01_sfnt_off00010507.bin
4c5c6381cb2f126cda14515a895c74da5ec7fa6872c049d38d2f9bd043bd4e69
pdf-font-stream PDF embedded font (sfnt) at offset 0x10507 11140 bytes
font_02_sfnt_off00012b49.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x12B49 4324 bytes