Malicious PDF — malware analysis report

Static analysis result for SHA-256 245b8a2b04475888…

MALICIOUS

PDF

73.8 KB Created: 2021-07-14 06:44:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 57e13678f56206cbedb7e93fca86b5a5 SHA-1: f67055667f30a9a2865cc2c81b492ad7fa7b6092 SHA-256: 245b8a2b04475888edc3c54aaa656555c0f8c8ab168eaa8263d94c16e65c0c94
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a phishing attempt. The PDF contains embedded URLs, suggesting it may redirect users to malicious sites or download further content. While no scripts were explicitly extracted, the PDF structure and heuristic firings point towards a malicious intent, likely related to delivering a phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7218

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/iXsW93xxTQA/square?utm_term=10+examples+of+rational+numbers
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e768a5e961b20f26f6a7a3/1625778341168/guyton_physiology_notes.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60edb8493d37cd087e6f14cf/1626191945260/difference_between_line_integral_and_surface_integral.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ecacc93631fd4ab81a334d/1626123465726/xusezu.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60edb0a5f827c554fda184a5/1626189989383/pms_a_week_after_period.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bed7.bin
987ed93a16f1d1799519cac181020ccd58425dcdca87024b900dc21326a8577f
pdf-font-stream PDF embedded font (sfnt) at offset 0xBED7 16640 bytes
font_01_sfnt_off0000ea11.bin
169be30e6a48554319c80ef1b1d53a256949feceab03edc707b9a5b15f101581
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA11 10936 bytes
font_02_sfnt_off00010332.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10332 16792 bytes