Malicious PDF — malware analysis report

Static analysis result for SHA-256 4bef20a471cf49c2…

MALICIOUS

PDF

76.4 KB Created: 2021-07-16 12:38:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 1defb408a3252f2ab742c37b3c4516d4 SHA-1: 96b4169aa34fd1b43bfbc10ed5ad03ea92306228 SHA-256: 4bef20a471cf49c2165481e5def06ba0e5f15c29415f1a7ac9cb3401caa8c436
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. The presence of embedded URLs, despite some being marked as benign, suggests an attempt to lure the user to malicious content. The ML classifier also strongly indicated maliciousness. The document body is heavily obfuscated and unreadable, preventing a more detailed analysis of its specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8907

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/NsX9ihectO0/square?utm_term=downfalls+high+chase
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f01e94086977531730754d/1626349205269/zidovu.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ede52230d23a755063fa5a/1626203426269/83376645951.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e88a1437eca442869a9955/1625852436389/69599838474.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f05cc8c872e80de5b327aa/1626365128616/zobuf.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60edc4b3a9d1f62037e01267/1626195123201/gk_answers_and_questions.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e87c2e33c3d3411a98cc36/1625848878893/xopogamisuxezoti.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c6e9.bin
6f8e8575c9f6875de9a13564529621bb84c0ee8c27b4de6335c8d0d0a5544837
pdf-font-stream PDF embedded font (sfnt) at offset 0xC6E9 10504 bytes
font_01_sfnt_off0000decd.bin
4b07c886651ec88f5404cc9442355e5756c288cde2eb658dac45cefe75157878
pdf-font-stream PDF embedded font (sfnt) at offset 0xDECD 18092 bytes
font_02_sfnt_off00010c75.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C75 16792 bytes