Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a5f6f5dc49c1fe4…

MALICIOUS

PDF

75.3 KB Created: 2021-07-14 09:15:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 64d7d78d00a16a86ca3c388d17b78841 SHA-1: ab08e425b8851225ef81b1a55863fe7a9563e6c8 SHA-256: 1a5f6f5dc49c1fe4630dc8b138b80098ad0b66c71ebe868c51f4ae2b1282a880
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs and the PDF structure suggest it is designed to lure users into clicking malicious links or downloading further payloads. Although no scripts were explicitly extracted, the PDF format itself can host malicious JavaScript, which is a common vector for exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7788

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/XMoLd4EPXkg/square?utm_term=gold+plating+gold+coast
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e88baaaec13c6ce7225756/1625852843102/16262889310.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e7cde9d0799e4214bff4ff/1625804265160/70699145828.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ed8d6df67381323ef91ee5/1626180973416/kinemikadijatusawer.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c3ab.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC3AB 16792 bytes
font_01_sfnt_off0000dbc2.bin
e17eacb5f2270f1af3ef237f7a031c9d4b0efe1fcf0f803103942555bd8444fa
pdf-font-stream PDF embedded font (sfnt) at offset 0xDBC2 10496 bytes
font_02_sfnt_off0000f387.bin
2b77185762eec99ae87ba2b3642164895aae073e6add71f382eb2a70ae4fd495
pdf-font-stream PDF embedded font (sfnt) at offset 0xF387 17444 bytes