Malicious PDF — malware analysis report

Static analysis result for SHA-256 39b730d21aa7b0a9…

MALICIOUS

PDF

89.3 KB Created: 2021-07-16 01:41:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 761781c26538fb1e236890b44acab440 SHA-1: 067880142a249919a671d07438cc9eadce179040 SHA-256: 39b730d21aa7b0a94c89ad025a89072c134a21e5110a0c0ce88e70a30511fc52
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. The PDF contains embedded URLs that point to external websites, suggesting an attempt to redirect users to malicious content. No scripts were extracted, but the presence of external URIs and the overall detection suggest a spearphishing attachment attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9526

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/u8n3KCQdUYc/square?utm_term=different+types+of+seminar
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee3d80462f394a1e42362b/1626226048975/homes_in_lavallette_nj.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60edce598f209f4d8282635d/1626197593901/how_do_i_know_how_old_my_bearded_dragon_is.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60edbdb8c6126f45c3de97f2/1626193336373/zepativax.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee0c7a33d4654651b98ae5/1626213498841/pijotezileto.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ede245e55429721e216fc9/1626202693113/convert_doc_to_in_word_2007.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e93b31f492d21a0f6bafe3/1625897777741/sufokebomuxoxin.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e843f37facf136447ebf57/1625834484006/81161433531.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f07b3bdd8e8d2fca6926bd/1626372923841/16610191995.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fa60.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA60 16792 bytes
font_01_sfnt_off00011277.bin
3178afa6ec90a280178dc3f06ee60399845ad763bfec15b9a1a86df8043c73af
pdf-font-stream PDF embedded font (sfnt) at offset 0x11277 10588 bytes
font_02_sfnt_off00012aac.bin
95ba55d7df14083871b5995ffa9df5c6243f874d3fdc812059c2e90a9ef5e802
pdf-font-stream PDF embedded font (sfnt) at offset 0x12AAC 17324 bytes