Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a7e01289cc6d015…

MALICIOUS

PDF

89.9 KB Created: 2021-07-14 01:49:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: ce9b0b6ba35b1d78c4f495329aff81a2 SHA-1: ba0a573ebf2de4fb02f292b7f72cdd1de6ce3801 SHA-256: 7a7e01289cc6d01562385a0ebb704f464b5360dd4d160a209caab2dcbd22c9f3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains multiple embedded URLs, one of which is associated with a phishing lure. Although no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to redirect the user to malicious content, likely for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9984

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/gPkW7oTCsL0/square?utm_term=partial+thickness+wound
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e91929787dde1a90adbc22/1625889065531/11188808702.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee136aeed6cd77ab5eebb4/1626215274965/uno_drinking_game_for_two.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e8ef920a287971af97c8a8/1625878418685/be_the_rose_that_grew_from_concrete.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee09b939b8260338661e9c/1626212793507/fipuxuwewamakisixusaf.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec7f9c19a16f038d61ed8a/1626111900604/tegovalenubegunuxe.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60eca3da0e7a3c5fba409121/1626121178994/14638969997.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ede1ec1c6c1a61d5255c9c/1626202604911/how_to_find_an_equation_that_is_parallel_to_another_equation.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ede881c450ee4730803a2e/1626204289411/36706522710.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ee0935115d504d3a8223c8/1626212661255/23318099539.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ed9bb7151a035e9e7b9e9e/1626184631565/biodiversity_is_threatened_by.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fcb0.bin
188c3d7a1aeb19b987fd3e41107ff4e5cce2710efe8e5e1d5e74d548a76ec94c
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCB0 16964 bytes
font_01_sfnt_off00012915.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12915 16792 bytes
font_02_sfnt_off0001412c.bin
c7ab709378918bb7fcb3a081050f42232b8e0e93e9d195d022fff855fa10eb8d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1412C 10748 bytes