Malicious PDF — malware analysis report

Static analysis result for SHA-256 09e882fbf6feb21d…

MALICIOUS

PDF

149.3 KB Created: 2021-07-14 06:40:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 63b4f8f268e9f299aa6dc79d0ea832f9 SHA-1: 84a8b43c185c0474b465cc48f5577e8b84d8ed97 SHA-256: 09e882fbf6feb21d819052372d39edc0d1ed5531918fe9af29a9abe49de93f6d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. The embedded URLs, although many are marked as benign, suggest an attempt to direct users to download potentially harmful content. The document body is heavily obfuscated, preventing a clear understanding of its specific lure, but the overall context points to a malicious PDF designed to trick users into executing a payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7718

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/CHqDoFjlE84/square?utm_term=archicad+to+pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e796dc95719b356d8efdfe/1625790172801/32298647536.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e7af9c23621b4743e1b58c/1625796508138/win10_loader_free_download.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e93a8c320dbd0de281dd64/1625897612871/35842387762.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60edc7da2799685454f6ae0b/1626195931100/riboruseduduwawuzuboxurub.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e9414012fb7d0b279470a4/1625899328424/call_of_duty_beta_apk_download.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ed7779f9a98d6db3add099/1626175353974/jovularililixunobub.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee5839b27e5958d591038a/1626232889949/31910941202.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e803dc23621b4743e58c1a/1625818076715/kaluris.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee2e217426fb5109f3ad59/1626222114065/96709141463.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001db73.bin
4e5828fab292e156cf84e9fa259403fb0328ddb44f6acbbecd9a87c3e3d45e07
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DB73 20532 bytes
font_01_sfnt_off00020ff7.bin
856b892691758dbf560c10df742a7fc9c664e0d8da903b1216b6d094c30b3cd5
pdf-font-stream PDF embedded font (sfnt) at offset 0x20FF7 10248 bytes
font_02_sfnt_off0002271f.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x2271F 16792 bytes
font_03_sfnt_off00023f2c.bin
bfe43d5959b2317135891740ee9f6bbd83044a2dfc391827d4c50438b6b55e15
pdf-font-stream PDF embedded font (sfnt) at offset 0x23F2C 1660 bytes