Malicious PDF — malware analysis report

Static analysis result for SHA-256 695df5ddec5b3654…

MALICIOUS

PDF

84.6 KB Created: 2021-07-22 00:13:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 8f635633e41500eb08168217f5f737c2 SHA-1: 197f4c741cc5f5ed91df397773f8e320f2a49c98 SHA-256: 695df5ddec5b3654ae4ab9f55c42e211f00b5485ca7ed6b896adcfca4ab592e5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample was flagged by a machine learning classifier and ClamAV as malicious, indicating a high likelihood of malicious intent. The presence of embedded URLs suggests the PDF is designed to lure users to external sites, likely for phishing or to download further malicious content. No scripts were extracted, but the PDF structure itself is suspicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9977

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/kVSxLQpkboc/square?utm_term=plains+and+river+valleys+offer+suitable+land+for
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f334f136db6462519ec1dc/1626551537170/pascaline_was_invented_by.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8d31ee2705b43630986d1/1625871134386/lofafona.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f085fba20a7272f5c16b90/1626375675413/i_wanna_get_drunk_with_you.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f7f82c592bc62482f101b7/1626863660865/60721125150.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f548a2c4d0d61e674ed6c6/1626687650761/be_kind_and_gentle.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e78ca8d93aeb546a0fcdd0/1625787560676/87953067071.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e85a20402b2441d131fce6/1625840161083/meloranibejubano.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60edd8fd930ff80baa0b8809/1626200317229/50116971966.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f333b6a8f65e35b6d81b2c/1626551224011/19551496257.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e7ce51d93aeb546a13e281/1625804370241/81589340881.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e931665ebba154a8fcd8f7/1625895270131/i_have_present_simple.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f20cf2b4d3bc79879c5ce8/1626475762522/93990467169.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f385471434f6354726aa1d/1626572103114/how_old_is_rapper_snoop_dogg.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f12a2dc08012782f81380f/1626417709937/90629150721.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ec9939704a383bbedb6537/1626118457786/dynasty_warriors_8_xtreme_legends_complete_edition_free_download.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f783a59956ae4f6d487d1c/1626833829185/wevezapatol.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ecb3b1f9f3f24b30c53a72/1626125233219/kesedevudupejowavogi.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e8ef3ce6a58043b68f2982/1625878332279/64220952770.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee838d9c71001bedf9addc/1626243981704/22550705042.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ee771fe7148d06bc7447b1/1626240799621/affect_and_effect_in_the_same_sentence.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60efeb7cc57e07264c2014b7/1626336124541/free_coffee_pouch_mockup.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e914812210ba6bce11a93e/1625887873138/nursing_diagnosis_for_thermoregulation.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f0abbc2c284d32c1672e2c/1626385340622/the_change_in_entropy_for_the_fusion_of_one_mole_of_ice_is.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e908.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE908 16792 bytes
font_01_sfnt_off0001011f.bin
7ef88fb575d3d7de09a05407b5d141ebfcb997808b2a8cb1ed2f39f1d080762d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1011F 10768 bytes
font_02_sfnt_off00011a09.bin
f9a18eb1091dd257c46e155552f6ea1651edb45f561e18c45fb603541c7a4f0b
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A09 16360 bytes