Malicious PDF — malware analysis report

Static analysis result for SHA-256 51052344d053b88b…

MALICIOUS

PDF

74.6 KB Created: 2021-07-13 17:02:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: b1d5adcd4b39bbaf910107372d6bedae SHA-1: 0f4b10fdca7195910174a7287e1620eecfec7306 SHA-256: 51052344d053b88be5cac2410e90fa9dc7164a947f9f7c8da67a1c6aae1eabe3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file was detected by ClamAV as Pdf.Phishing.Trojan-d2568dad23a94d95, and an ML classifier also flagged it as malicious. The presence of embedded URLs, though currently marked as benign, suggests an attempt to redirect the user. The PDF structure itself contains duplicate objects, which can be a characteristic of malicious PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8028

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/jEScUJLm1bs/square?utm_term=difference+between+semi+permanent+and+temporary+hair+dye
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e95d0f19a9f87deb749c89/1625906447154/dry_gallons_to_cubic_yards.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec8fadbcf8be39b5063399/1626116014108/united_feature_crossword_puzzle_answers.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e932c3cc7c0864592772a2/1625895619210/the_fixer_read_online.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c1a1.bin
008ad20183e4398106654c948f84373b1437d3ecc8efcd3b7e9495d4c7bbddcc
pdf-font-stream PDF embedded font (sfnt) at offset 0xC1A1 16496 bytes
font_01_sfnt_off0000ec30.bin
bb48f280f5837e126bcbf452b4a1dc3445f2ac20297c40aaad096b96e27c1668
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC30 11180 bytes
font_02_sfnt_off0001060c.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1060C 16792 bytes