Malicious PDF — malware analysis report

Static analysis result for SHA-256 80e40286831cc160…

MALICIOUS

PDF

83.5 KB Created: 2021-07-13 05:35:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 6f0a4c852a2f1b57bcbf183c04e0253b SHA-1: 088253d67501d624123b888836d96a0f7c681a7b SHA-256: 80e40286831cc16028cab6a0e23bdf30f11b964c971108970e2d1c68e50b8230
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains an embedded URI pointing to a suspicious external URL. ClamAV detection and ML classification further indicate malicious intent, likely phishing or malware distribution. No scripts were extracted, but the presence of the external URL suggests an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5817

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ketchas.ru/square?utm_term=work+breakdown+structure+for+hospital+construction
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ecc81d410b6f53fe143666/1626130461935/dirty_text_messages_to_send_to_a_guy.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60eca39f80388a1034da1030/1626121119996/sweller_cognitive_load_theory.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ecc3b26230952f42cf65e7/1626129330198/81329773620.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ecc7e008f5654265247252/1626130401099/south_of_france_cities.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e613.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE613 16792 bytes
font_01_sfnt_off0000fe25.bin
8bc9ebc767d87bf6125b0877311053c26b5435377a9a78c13011d522b6d451dc
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE25 16288 bytes
font_02_sfnt_off00012830.bin
1993621f3053c3de938e8beab2f3380b28e9384882f5bd88cb7d140535316697
pdf-font-stream PDF embedded font (sfnt) at offset 0x12830 11128 bytes