Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d520fd0f65d02d7…

MALICIOUS

PDF

87.1 KB Created: 2021-07-13 22:12:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 5f4e6dd71509b62131676397f3588f69 SHA-1: 939cab885d2bdbe815e59106c8a43e715d5cea2b SHA-256: 3d520fd0f65d02d74c5f557a751a3335630f3b9e0467f7d165d4763297c89352
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was identified as malicious by multiple security heuristics, including a machine learning classifier and ClamAV, which flagged it as a phishing trojan. The file contains embedded URLs, suggesting it is designed to lure users to malicious sites or download further payloads. The presence of duplicate object bodies in the PDF structure is also a suspicious indicator.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8840

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/nCRFBnYrBHY/square?utm_term=english+grammar+direct+and+indirect+speech+exercises+with+answers+pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e8f864e6a58043b68fc45a/1625880676206/types_of_environmental_impacts.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e928e52dabf2723554a3d1/1625893094091/android_kunjappan_full_movie_watch_online_tamilrockers.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60edde4a7ce58f02ed93eb3e/1626201674716/sidebutimudoxikelowo.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ecab95c81c37306b329cf2/1626123157692/rurutonema.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e907746e2672579439c70a/1625884532744/kazezegabadugizisevujuki.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e8258cba333063f17b89c5/1625826701090/role_of_bees_in_ecosystem.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60eda5f0262c1d4011354f15/1626187248844/english_for_airline_business.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f13d.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF13D 16792 bytes
font_01_sfnt_off00010954.bin
d38c8a905009f4dbf207c742c34803b4a0b414dd920e505ed629a669a87efc50
pdf-font-stream PDF embedded font (sfnt) at offset 0x10954 11120 bytes
font_02_sfnt_off000122e2.bin
f18886045cece981d21215617d0133774cfbd47ad4f0689485c01d99ae0e2c9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x122E2 16592 bytes