Malicious PDF — malware analysis report

Static analysis result for SHA-256 806d0899a20cf79c…

MALICIOUS

PDF

76.1 KB Created: 2021-07-16 20:19:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 898cdc2277a1550b09e5ce40fd0f5112 SHA-1: 72442c8c9a5361ed5d81df311f2b6c0291f4c347 SHA-256: 806d0899a20cf79c904ae89370b8fd0944204be80a1f784464453e85be026aae
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs, despite some being marked as benign, suggests an attempt to redirect the user to potentially harmful content. The document body is heavily obfuscated, preventing a clear understanding of its specific lure, but the overall structure and heuristic firings point towards a phishing or credential harvesting attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9163

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/kVSxLQpkboc/square?utm_term=how+to+scan+a+large+document+to+pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60eda7f7c7772f26c851f9cb/1626187767459/43216989688.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60eceb37f8b4e244e4f7e16c/1626139448209/funny_quotes_by_famous_people.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e923bac91b61347ea3cf4f/1625891770538/34106291849.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee2b09ab0cb8743be33ab8/1626221321541/hear_my_prayer_o_lord_from_the_ends_of_the_earth_i_cry.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e9355c12fb7d0b2794150b/1625896284312/quick_and_easy_lasagna.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec808cdd2ac847ff7e5929/1626112140487/timing_cover_gasket_leak_cost.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e8d4fa781e3e37a185c26a/1625871611139/how_to_know_if_inpods_12s_is_fully_charged.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c8ee.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC8EE 16792 bytes
font_01_sfnt_off0000e105.bin
cb326d2144a97a5ed9de6660385e9c18c02300ad436bf6f6cbe03cf40de7f5be
pdf-font-stream PDF embedded font (sfnt) at offset 0xE105 11048 bytes
font_02_sfnt_off0000fa9b.bin
c60bf84d1beb31f1aafefa5d4950e6e755d25e91bb5e4e05d2e83997a2585223
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA9B 16196 bytes