Malicious PDF — malware analysis report

Static analysis result for SHA-256 34a35ea7034b56af…

MALICIOUS

PDF

189.4 KB Created: 2021-03-18 20:29:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 948c63047738e3dbafeb0f9149dd2a90 SHA-1: 901984b72ab7c14b556e0d286aebe8eb979cac11 SHA-256: 34a35ea7034b56af6f07f43a274acf1e317bf99282f2d014d60231e6436783a3
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains heuristics indicating it is a phishing lure, specifically mentioning invoice or payment language. It embeds an external URI pointing to 'midufefew.ru', which is highly suspicious. While no scripts were explicitly extracted, the PDF structure and embedded URI strongly suggest a phishing attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=capital+of+bolivia+2020
    • http://powerpoint4you.ru/95457863967t1i95.pdf
    • http://temppicture.xyz/94802755249w8cdv.pdf
    • http://investmag.org/228619441466jh2q.pdf
    • http://bellissimo.online/lucent_english_grammar_book_in_hindimpt9e.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fuwawibu/92143669331.pdf
    • http://suzufazelebumu.rf.gd/binixikepujatalevokalaxex.pdf
    • https://s3.amazonaws.com/vifusupegiza/letter_format_for_schengen_visa_application.pdf
    • https://s3.amazonaws.com/wanalovum/83260705960.pdf
    • https://s3.amazonaws.com/fovezewi/73873425164.pdf
    • https://s3.amazonaws.com/toguvaju/cbo_full_form_in_law.pdf
    • http://xisewidudulad.rf.gd/banogurej.pdf
    • http://kupikobu.epizy.com/rufipafedup.pdf
    • https://s3.amazonaws.com/jevelel/63613752766.pdf
    • http://zapemapozo.rf.gd/tijojusedovoxubapetaxijo.pdf
    • https://s3.amazonaws.com/wemupajese/bipebinufug.pdf
    • https://s3.amazonaws.com/xovekolamoxe/monthly_planner_template_excel_2018.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00027beb.bin
3cd694d0766ad7e60dddc0f36f3c3ea7f123f8ca7323111a1765c9e9d20930cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x27BEB 6040 bytes
font_01_sfnt_off000290d1.bin
83d0f5cfeff288e055735a370af140d4d442a5ee3bf5dd14769ccaed5bc19aa1
pdf-font-stream PDF embedded font (sfnt) at offset 0x290D1 5000 bytes
font_02_sfnt_off0002a1e9.bin
cd48359a549aed82b8f63063a08cdf354aca0d7e6c3dbffee8de8067e79af45a
pdf-font-stream PDF embedded font (sfnt) at offset 0x2A1E9 15320 bytes
font_03_sfnt_off0002d23b.bin
1aa95217aa9d98eba83dfbb9ca906677227e5a0072974a50f78cbdc332c22f63
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D23B 16064 bytes