Malicious PDF — malware analysis report

Static analysis result for SHA-256 87b3d5c84315c4b9…

MALICIOUS

PDF

105.0 KB Created: 2021-06-01 16:40:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bcd41f30fa7785a46ef55c451bc1e503 SHA-1: 3cd5578858496ad57dcf6ffe42f1bd7228b64285 SHA-256: 87b3d5c84315c4b94c9941c6fc6ec61c9267f69059337a487126d0954b444751
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded external URI pointing to 'https://midufefew.ru/123?utm_term=arabic+mehndi+pictures', which is a strong indicator of a phishing or malware distribution attempt. The document body appears to be corrupted or heavily obfuscated, preventing a clear understanding of its specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/123?utm_term=arabic+mehndi+pictures
    • https://cdn-cms.f-static.net/uploads/4404528/normal_602f92ab200ca.pdf
    • https://static.s123-cdn-static.com/uploads/4402032/normal_60076f924c6ff.pdf
    • https://static.s123-cdn-static.com/uploads/4484994/normal_6003703627f22.pdf
    • https://cdn-cms.f-static.net/uploads/4451205/normal_60228c9dee1ad.pdf
    • https://cdn-cms.f-static.net/uploads/4369305/normal_6022e5b58ea45.pdf
    • https://cdn-cms.f-static.net/uploads/4418987/normal_600c9d8a267f8.pdf
    • https://static.s123-cdn-static.com/uploads/4486534/normal_5fdcfa3e27a87.pdf
    • https://static.s123-cdn-static-d.com/uploads/4492257/normal_60b007370d609.pdf
    • https://cdn-cms.f-static.net/uploads/4370059/normal_601462d536574.pdf
    • https://static.s123-cdn-static.com/uploads/4450507/normal_5fe1c954c6848.pdf
    • https://cdn-cms.f-static.net/uploads/4499979/normal_5fd1b507a3011.pdf
    • https://cdn-cms.f-static.net/uploads/4380209/normal_6018604ae0e73.pdf
    • https://static.s123-cdn-static.com/uploads/4376869/normal_5ff34ab3d220c.pdf
    • https://cdn-cms.f-static.net/uploads/4383132/normal_605c11a2e5b2f.pdf
    • https://static.s123-cdn-static.com/uploads/4478932/normal_5fcb5f5f26155.pdf
    • https://cdn-cms.f-static.net/uploads/4456676/normal_6032e65094515.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/42b81070-6660-4fa1-ae4c-d2eb9f13dc2f/favedolifa.pdf
    • https://uploads.strikinglycdn.com/files/4a6cafd1-677e-43b4-9926-244b633ad97f/what_do_black_jelly_beans_taste_like.pdf
    • https://uploads.strikinglycdn.com/files/2fb29818-ecb3-46ec-99af-f6a94e66bcf1/75559234333.pdf
    • http://bupataved.pbworks.com/w/file/fetch/144427617/pederiwexogesifinogases.pdf
    • http://niwomif.pbworks.com/f/xutiwif.pdf
    • http://kevuxezedila.pbworks.com/f/53877790090.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015f8d.bin
6c3e9674ac8de470106a07ee16a17b32f83fb19e75c8795585dfc445c55d4665
pdf-font-stream PDF embedded font (sfnt) at offset 0x15F8D 5408 bytes
font_01_sfnt_off000171be.bin
0ef5244b4f279b11b950b4d13a26d5b40c44454bd092b078b10794dc94c33ed7
pdf-font-stream PDF embedded font (sfnt) at offset 0x171BE 10796 bytes