Malicious PDF — malware analysis report

Static analysis result for SHA-256 6468ffbcb47506c6…

MALICIOUS

PDF

73.9 KB Created: 2021-07-19 07:24:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: b31bd4f678a19441c95daf76e0ce779d SHA-1: 4a4d12555208b8fe4964c3397542d8aa268b55aa SHA-256: 6468ffbcb47506c628c6c6a73bce592131ae04f98d7cf2679487f5f101cb3c4a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ML classifiers and ClamAV, indicating it's a phishing trojan. The PDF contains embedded URLs, suggesting a lure to external malicious content. While no scripts were explicitly extracted, the PDF structure and detection suggest it's designed to exploit users through deceptive content, likely delivered via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8802

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/IdU8rIDf9lQ/square?utm_term=what+is+a+side+strain
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f0187779f953043cbf8ea0/1626347639262/69257465287.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e8c8c13add050c1b4b6405/1625868481454/firbolg_character_creator.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ed4408c76d6b0ba00bcf51/1626162185065/94575868508.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f04beee120bb33bad19563/1626360815023/nepeke.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60effdc997dca740078d7e07/1626340810018/word_document_to_a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c133.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC133 16792 bytes
font_01_sfnt_off0000d945.bin
1160d42963a4acd34a71eb8b9094ac9b72b4c43ebe92973ab81869049955fe36
pdf-font-stream PDF embedded font (sfnt) at offset 0xD945 16864 bytes
font_02_sfnt_off00010507.bin
d47b1ea2ae2d5a196c4ca6b991aa74491c55ead39fb9fd0fbf5ff35a404c5a41
pdf-font-stream PDF embedded font (sfnt) at offset 0x10507 10172 bytes