Malicious PDF — malware analysis report

Static analysis result for SHA-256 171fe88f21ac818e…

MALICIOUS

PDF

85.0 KB Created: 2021-07-14 05:09:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 2b55cd3d06c1377d9f5902cfc444467f SHA-1: 3d7b6c8f0db5b7e3745b4300b72c9729411f8761 SHA-256: 171fe88f21ac818e296953455b6cc2bd7c876b9adde789c2cfe55f325d5e626d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded URLs, despite some being marked as benign, suggests an attempt to redirect the user to potentially harmful content. The PDF structure and embedded artifacts are consistent with phishing or malware delivery techniques.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6359

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/ZFaGRQ6RLlg/square?utm_term=a+worthy+weapon+quest
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e9202e2dabf27235544d64/1625890862560/dplyr_if_else_multiple_conditions.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60eda5621a2ce466740c8871/1626187106158/well_and_septic_cost.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60edc7aa3e0111437125d173/1626195882560/lather__smooth_snow_globe_gift_dome.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9ee.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9EE 16792 bytes
font_01_sfnt_off00010200.bin
bad10d2ecdabfdaa2a4b0dc5c49d196f4ba0fc5a5173b778bdc1bd3d10fceeca
pdf-font-stream PDF embedded font (sfnt) at offset 0x10200 16996 bytes
font_02_sfnt_off00012e5f.bin
ec58654d7d2aa709684b979cd050f43c6f3d1bace509231fa322feffd8bd90a6
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E5F 10640 bytes