Malicious PDF — malware analysis report

Static analysis result for SHA-256 1df730dda5885a4d…

MALICIOUS

PDF

78.5 KB Created: 2021-07-15 13:31:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: cd1b1c4788644e32a97d70c8bbb0e351 SHA-1: b7a47db48f75b18a34ec7d2f819c41c480b11301 SHA-256: 1df730dda5885a4df5ebf19c9356e69cf1901b33d78cd6dada0c756da4982b8f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a PDF file flagged by ML classifiers and ClamAV as malicious. It contains embedded URLs that likely lead to phishing or malware distribution sites. Although no scripts were explicitly extracted, the presence of embedded URLs and the nature of the detection suggest an attempt to trick the user into visiting a malicious resource, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8755

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/k6oGaauGqGM/square?utm_term=warframe+how+to+rank+up+fast
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ee83d7b82b304768643e48/1626244055732/35405842999.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ed9287f8b4e244e400910b/1626182279431/murazomorobif.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ee751ae7148d06bc74334c/1626240282425/bergers_uncertainty_reduction_theory.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60efef191b42e761db878364/1626337050325/jilafifezulagekiku.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ee2f5777e2cd4113eeff4f/1626222423110/86270040824.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ee77fd5f7927514e409cbd/1626241021908/causation_in_criminal_law.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60effe03161c06605437aef2/1626340867915/us_9_foot_size.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d310.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD310 16792 bytes
font_01_sfnt_off0000eb22.bin
b0e0ca1f65831140bd21fac530989ce63d349f08d6a954f4ff6179bca1e1b207
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB22 16256 bytes
font_02_sfnt_off00011550.bin
e12ea0e19683ac3e2fabdee3a3940782061b8d86286ad08917448d07ebd9b908
pdf-font-stream PDF embedded font (sfnt) at offset 0x11550 10756 bytes