Malicious PDF — malware analysis report

Static analysis result for SHA-256 644a200ab850b638…

MALICIOUS

PDF

80.6 KB Created: 2021-07-15 22:14:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: ebb128c49f621467d62ea55aa51bfc21 SHA-1: 783693495103027eed5785af3aff536ffc6fe30b SHA-256: 644a200ab850b638d45e9da20e6846a4227b8d65e550b0d268efc819a100af11
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by a machine learning classifier and ClamAV, with heuristics indicating the presence of external URIs and an urgency lure. Although the document body is heavily obfuscated and unreadable, the presence of an embedded URI and the urgency heuristic suggest a phishing or credential harvesting attempt. No scripts were extracted, limiting further analysis of the attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9478

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/UQ8tT55rDuk/square?utm_term=example+of+reprimand
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f0024b4980ba6b3b6eb312/1626341963429/important_philippine_cultures_which_are_needed_to_be_preserved_for_cultural_identity.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec9561831aaf5e928bc9ec/1626117474143/segalazoluwapoxojunobovi.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e7a93ed56f0f36126e5df2/1625794878758/calories_in_1_glass_of_chocolate_milk.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee773b0981f36585a560e2/1626240827667/jenopapopafufix.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f0400136870d1a2dbab90f/1626357761776/martin_luther_king_1517.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ee7f9ab1f8b95648897322/1626242971295/nuzejox.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e95ea63ba7d954d547ee53/1625906854634/memufagujeruge.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60edfb4aafeffb59e6750d61/1626209098243/name_the_chemical_carcinogen_which_causes_prostate_cancer.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dd4f.bin
3b765e67b668f64b846d07f1f28cac56ba39978b6be905591ec0523bfef32b56
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD4F 10476 bytes
font_01_sfnt_off0000f4fc.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4FC 16792 bytes
font_02_sfnt_off00010d0e.bin
c7a6eed90432e42cdb2127ae09def6a05db2a558325e928c5953727cffe9074c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D0E 15688 bytes