Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a912cdd83c5dbff…

MALICIOUS

PDF

91.7 KB Created: 2021-07-19 20:30:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 6a59924315f72d23273d70183f32c8d5 SHA-1: b2953aa4e29ae6d2310b5386d4d5468a86771d5b SHA-256: 4a912cdd83c5dbffb8454c766e80f059918c74a7e1f05cf5327bdde9f13f79d2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, with ClamAV identifying it as a phishing trojan. The presence of embedded URLs, though currently classified as benign, suggests an attempt to redirect the user to malicious content. The file's structure also indicates potential for exploiting PDF vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9127

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/r_nBws6J8g8/square?utm_term=cell+dragon+ball+z+first+form
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e94606f492d21a0f6bfec5/1625900550361/attorney_and_solicitor_difference.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e8017c687a3d659a4d9dd0/1625817468637/genidekelepojazox.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f14fb04bb49071de1b2946/1626427312335/highest_common_factor_of_96_and_60.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f34afb1db272198f970230/1626557179446/writing_equations_of_transformed_functions_worksheet.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f06471d941835b131892ca/1626367089779/6699961021.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec8bf90cf33f708d7b4ac0/1626115065366/fererogizowodekojexego.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60edbbfa3b2f984ee88398de/1626192891086/why_do_you_conduct_research.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f280a2668793736d2874c4/1626505378798/the_most_beautiful_actress_in_korea.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8a9.bin
e1db11455b8f8b56a9b5e177c09240edaf9ec3f3b24a6b50706eadb01514d4d7
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8A9 2464 bytes
font_01_sfnt_off0001037b.bin
df9e2601d854dfc008aceade6aa3f1ba18df22d44ed3d1c7c985654a92ae1e7f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1037B 17484 bytes
font_02_sfnt_off00013100.bin
44e649e61241160462ae7f3bd81c4c597329ea1252f9ee9cad7ffc6f5aeb9bc2
pdf-font-stream PDF embedded font (sfnt) at offset 0x13100 10928 bytes
font_03_sfnt_off00014a23.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x14A23 16792 bytes