Malicious PDF — malware analysis report

Static analysis result for SHA-256 97bde9787b6ba7f8…

MALICIOUS

PDF

81.0 KB Created: 2021-04-28 06:44:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3eab14dc329c60e508ed44a280fa025d SHA-1: 7273331ba7d5e3498b0326b639d247ef44b90d70 SHA-256: 97bde9787b6ba7f845d14cd2be901ddbf9dc4654eb3bef20a863e539a474db84
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and ML classifiers indicated a high probability of maliciousness. An external URI pointing to 'pelibifir.ru' was extracted, which is likely used for phishing or malware distribution. The document body, though partially corrupted, contains text related to skincare, suggesting a lure to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=how+to+get+rid+of+pimple+marks+fast
    • https://static.s123-cdn-static.com/uploads/4388405/normal_5ff2d63e8fbb6.pdf
    • http://successinyourlif.website/vulcan_pop_bubble_shooter_game2h3n2.pdf
    • http://fajasated.mywebcommunity.org/sizanulolexu.pdf
    • http://beamorem.com/8257073712450uvf.pdf
    • https://cdn-cms.f-static.net/uploads/4410191/normal_604cf61198ef6.pdf
    • https://static.s123-cdn-static.com/uploads/4420604/normal_6007e5203773e.pdf
    • http://getplafond.xyz/bose_901_equalizer_series_vieb49i.pdf
    • http://gepopusoka.mypressonline.com/fl_studio_price_south_africa.pdf
    • http://kigumelez.medianewsonline.com/timex_alarm_clock_nature_sounds.pdf
    • http://scandisvet.ru/kapesukzd1se.pdf
    • https://static.s123-cdn-static.com/uploads/4379602/normal_5fc744a51e4f6.pdf
    • https://cdn-cms.f-static.net/uploads/4500692/normal_604000bd6a5fd.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/22b23367-9595-4bd2-9777-fdbc737585f6/ps3_controller_battery_life_vs_ps4.pdf
    • https://uploads.strikinglycdn.com/files/25440f76-1d2b-49e6-ae5b-3967f623e4c4/vakamer.pdf
    • https://uploads.strikinglycdn.com/files/2286da0e-58cd-4f2b-81d7-18b2ff162f38/61473901403.pdf
    • https://uploads.strikinglycdn.com/files/7611597d-57c6-4050-8657-f955bf12d31a/fender_passport_pd_250_battery_pack.pdf
    • https://uploads.strikinglycdn.com/files/d5ffa4df-6e29-49bf-9cb1-eb257c375a28/64939667571.pdf
    • https://uploads.strikinglycdn.com/files/1b8b42ec-670f-4405-ad72-f8875884967d/how_to_service_daikin_ducted_air_conditioner.pdf
    • https://uploads.strikinglycdn.com/files/4cba55f5-718a-4bef-9a17-60f52b7053a1/where_is_the_best_place_to_put_a_carbon_monoxide_alarm.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb78.bin
ae974b2583726dc0d03c09f41fea2d5c2ca4808b4b914969b770e77ed023073c
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB78 5476 bytes
font_01_sfnt_off00010e1c.bin
4ca87160b0063c11ede9dfb4258830bc866ef395ad80946014d1b41f132b09b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E1C 12080 bytes