Malicious PDF — malware analysis report

Static analysis result for SHA-256 067d0d6ac360704f…

MALICIOUS

PDF

75.2 KB Created: 2021-07-16 18:21:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: f6626a30fc35cbbc5d1714a5e21b9346 SHA-1: bf32bea4625746843045846dad57790c506cf586 SHA-256: 067d0d6ac360704f51a0618c204961a20afbe19e015c5916f29e741c97fc3820
96 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample was flagged by both machine learning and ClamAV as malicious, with ClamAV specifically identifying it as a phishing trojan. The presence of embedded URIs, even if some are benign, suggests an attempt to redirect the user or download additional content. The PDF structure itself shows signs of manipulation, such as duplicate object bodies, which are common in exploit-laden PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9937

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/gOBB6uaVNRA/square?utm_term=how+many+electrons+are+there+in+each+shell
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e91af73f195e1e4036248f/1625889527321/the_expendables_1999.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec7e29700aa07a7894516b/1626111530191/vusolemefatiwopemagujinog.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e7d2286e46386ca3c02d6e/1625805352793/approximation_in_a_sentence.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60eca44cc426b81e8302f192/1626121292384/40706620616.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee90068e3fff2bd3c4aff2/1626247174812/35785649950.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60efeae136870d1a2db668d2/1626335969390/ac_motor_coil_winding.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e7e34dd56f0f361271643e/1625809741851/differential_equations_in_physics.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec7f770cf33f708d79f1b5/1626111863376/cisco_internet_of_everything_final_exam_answers.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60f01a1ae4fb0f110d7cac35/1626348059519/22917887424.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c3c6.bin
4f6ecfdc150687da722b452efe27906241835ad689f6989b710e71abce3a8bf9
pdf-font-stream PDF embedded font (sfnt) at offset 0xC3C6 17028 bytes
font_01_sfnt_off0000f056.bin
7cf019d8fe4990f8eff3e9cf05ebccb93f0ca757e95544ad44f95fb820f81b2d
pdf-font-stream PDF embedded font (sfnt) at offset 0xF056 10684 bytes
font_02_sfnt_off000108aa.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x108AA 16792 bytes