Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e83bfde64201297…

MALICIOUS

PDF

75.9 KB Created: 2021-07-13 09:48:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: d6e4910b05aa801899f774db36dc5ae5 SHA-1: f604164352711013ac32090fe01e8dc51c33dd3b SHA-256: 5e83bfde6420129784af57eed92a8bf737f89041d50d64d05a8bf938c4e7e4b1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs, despite some being marked as benign, suggests an attempt to lure users to external resources. The file's structure and heuristic firings point towards it being used as a delivery mechanism for further malicious content, likely through exploitation of PDF vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8791

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/qI_NY8u86tA/square?utm_term=rafter+roof+framing
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ec912445711547b6a755a1/1626116388387/10th_class_chemistry_mcqs_chapter_wise.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e8dfdd12fb7d0b278fe2d8/1625874397850/12980972910.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e8fe2a5ebba154a8fab047/1625882154871/mudegowenuzukanade.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec7836154eb17b6848df79/1626110006493/gaxarizi.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e84c84dc22a026a1169d97/1625836676354/vofakiwedolelujijanul.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ca27.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xCA27 16792 bytes
font_01_sfnt_off0000e239.bin
86f4be4711ab4dac56205daac094285665710b965a8a3595b42d3b7ffd6b08ca
pdf-font-stream PDF embedded font (sfnt) at offset 0xE239 16292 bytes
font_02_sfnt_off00010c55.bin
d4d350b2654903cc47c4f57387295d75eaa46dfc5cf0d53fd0f49d51ce12e887
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C55 10388 bytes