Malicious PDF — malware analysis report

Static analysis result for SHA-256 086c12ddc584f93a…

MALICIOUS

PDF

79.4 KB Created: 2021-07-12 21:50:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: e974ec9a4ac5f2d1cb984a9e73461a9a SHA-1: 5be8e1997eb3e34e3735b035ab19b4861a3e65dd SHA-256: 086c12ddc584f93a568d0bd75b3672e6f3be109ac20e190db02c5983b2182218
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded URLs, despite some being marked as benign, suggests an attempt to redirect the user to potentially harmful content. The PDF structure itself appears to be exploited, as indicated by the 'PDF_DUPLICATE_OBJ_BODY_INCREMENTAL' heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8896

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/UQ8tT55rDuk/square?utm_term=my+albumin+is+low
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec8995fa40056e74d2d96a/1626114453595/rixujibelanepawikigegoba.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8cf10c81c3e1fd729bd44/1625870096722/the_story_the_teacher_told_us_was_very_interesting.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e9602358c6623f0384341c/1625907235778/10730043473.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e94bcef4fe78435a3c0501/1625902031029/dye_mixer_industrial_foregoing.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e790405c1b8460033a7735/1625788480683/11th_chemistry_lesson_2_book_back_answers.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e86afbf244fe4368172269/1625844475575/xobedefefujimura.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e82a55d0799e4214c37587/1625827925150/tumijinizozowiravule.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000da37.bin
fb90dc5efe3e2d48d1d3d86b1fe23e1fb3a9297c8127f2291f835896c53be460
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA37 10372 bytes
font_01_sfnt_off0000f1a5.bin
b7f5ef4729e7564a22cfe3157e629d5e7edaf823d520eafaf2b8838c9ed009a6
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1A5 15608 bytes
font_02_sfnt_off000119d6.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x119D6 16792 bytes