Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ba02057524cd59b…

MALICIOUS

PDF

93.6 KB Created: 2021-07-23 03:39:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: f490f92cfa7fd565cdd7698339a6e842 SHA-1: f5178cbe9109c1a04d9335e8f6e883652dc3440f SHA-256: 5ba02057524cd59b2f9e30319967d282d93d46d54a95f641b8cfc77d03c44ff0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF was flagged by ML classifiers and ClamAV as malicious, indicating a high likelihood of malicious intent. The presence of embedded URLs, even if some are benign, suggests an attempt to direct the user to external content. The document body is heavily obfuscated, preventing a clear understanding of its specific lure, but the overall context points to a phishing or credential harvesting attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/-MXWpcYQ7kA/square?utm_term=past+simple+not+go
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f809c83bf5736ec38cbe0e/1626868168993/english_songs_for_school_students.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f5e0e539a8f232034db72b/1626726629855/homogeneous_differential_equation_solver.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee62444d490f672754790e/1626235460486/dojeze.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f1f3a6a621f47bfcf61a06/1626469287088/27789648956.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e7a914dbb92d34f5ac03e1/1625794836597/velifabon.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f4c69936db646251b0a39c/1626654361738/72757638585.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f5149a0dbab00e46f7c2e5/1626674330994/asian_with_bleached_hair.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f444d69c7c9f0ea9a33cbf/1626621142366/federal_state_example.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f100dbb348e55d1c4fb633/1626407131787/jazexowema.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f285f71d35070742166fa2/1626506743338/harbour_town_stores.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f9572ec2d04918d4c57ea2/1626953518546/jexivaguzosi.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f323aca9adb72803a47bdd/1626547116446/43060528337.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee4665537273346e305656/1626228325430/poweliro.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f6140a2fd42108f73bbabb/1626739722335/the_french_impressionists.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ec77dbde8c3264fe5dabfc/1626109915880/meaning_of_at_his_wits_end.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f9badf2f569a293aa5f5df/1626979039962/the_flash_by_grant_morrison_and_mark_millar.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e6ee.bin
0031c3c2ba3b90d97080a977e9401a565477d1436ef4c4b456ff0784fff818bd
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6EE 17160 bytes
font_01_sfnt_off00010064.bin
1325dbbe50f449107f85a03de3e50cb67146f2b812af1d0846948c6cdcd39b51
pdf-font-stream PDF embedded font (sfnt) at offset 0x10064 18144 bytes
font_02_sfnt_off00012e92.bin
5221cc56e96b657ff7c15f49bf1fbf1b5222e15cd7ffd769ce953162a3e53832
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E92 2064 bytes
font_03_sfnt_off000137d2.bin
7ce251728d9dc1fa80a6fe9ac4d7d64ffe2b93bf7e45d63cc7c89c2f27565969
pdf-font-stream PDF embedded font (sfnt) at offset 0x137D2 10496 bytes
font_04_sfnt_off00014faf.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x14FAF 16792 bytes