Malicious PDF — malware analysis report

Static analysis result for SHA-256 303dffc043d1a586…

MALICIOUS

PDF

77.6 KB Created: 2021-07-17 00:23:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: df24e0442b918737b547bcbcc387a115 SHA-1: 56e0016a52b6c1dea91cabb31e21293439ac6314 SHA-256: 303dffc043d1a58652bef49af08008bc2c5286adc16995f8f5780dbd8804b840
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file was detected as malicious by ClamAV and an ML classifier, indicating it is likely a phishing or social engineering lure. The presence of embedded URLs, though marked as benign, suggests an attempt to redirect the user to malicious content or download further stages. The PDF structure itself contains anomalies that contribute to its malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9214

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/WVKuihPcy9U/square?utm_term=hurry+up+and+appear+with+note
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f152b2f32be22f00787833/1626428082527/gravity_sungha_jung_tabs.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f1f5b1f06bb7307724372e/1626469809838/dialogue_with_an_atheist.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ee61f0b82b30476862afa1/1626235376776/financial_markets_multiple_choice_questions_and_answers.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f1f49e4d12915be4e9bedf/1626469534419/noble_meaning_in_bengali.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f0642b87ee3075eb521ef5/1626367019337/vulolazibaw.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f096c99d73d13cc78b7baa/1626379977414/selective_non_catalytic_reduction.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e80bb0f4d7c53d8b151f2f/1625820080879/another_name_for_digoxin.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cec1.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xCEC1 16792 bytes
font_01_sfnt_off0000e6d3.bin
7b8186cf3600648dd0eccd6a1b76680151192b00bff6346ca0d12c068175be40
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6D3 16752 bytes
font_02_sfnt_off0001127e.bin
a5b1c2c7e57b7a1e717a1e8ecc52d36d4c0eb4673e986f76f53691298fba60d1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1127E 10568 bytes