Malicious PDF — malware analysis report

Static analysis result for SHA-256 8279671fc7e723da…

MALICIOUS

PDF

84.9 KB Created: 2021-07-15 22:17:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: cfbcbb8417e4d5bc7f7b4bacee863948 SHA-1: d299243f9fa12e9bc1574020833de69e2f14dd3d SHA-256: 8279671fc7e723da40b6f1ccae8e6503ccb0eb538563419c1063548edf6f67e6
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a phishing classification. It contains embedded URLs that lead to benign content, but the PDF structure itself is suspicious due to duplicate object bodies. The primary attack vector appears to be social engineering via a malicious document, likely intended to trick users into clicking links for further compromise.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4119

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/NsX9ihectO0/square?utm_term=greg+and+steven+fusion
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f03d58c00d13116b478ea3/1626357080319/cbse_9th_science_textbook_exercise_answers.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ed4f1daf55617121247034/1626165021473/hire_purchase_companies.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ee22062ee8b51fd9334d56/1626219015107/shikellamy_administration_office.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ec8f95f83a7f26ecd1832b/1626115989987/kingdom_in_chaos_mod_apk_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d5c2.bin
14e72c0e3be84bd057e02e4fbfdf698d1c3ff90c6b683808567eaf7b91eb5dc4
pdf-font-stream PDF embedded font (sfnt) at offset 0xD5C2 10688 bytes
font_01_sfnt_off0000ee44.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE44 16792 bytes
font_02_sfnt_off00010655.bin
74ea40c6abafff908ba0a862ebf25ee1d47d31f530ca964bdc695191fb21b084
pdf-font-stream PDF embedded font (sfnt) at offset 0x10655 16116 bytes
font_03_sfnt_off00011ba9.bin
04ff4c26781179472b56a5588d287dce4364b788dc433703fb7729e2aefbff58
pdf-font-stream PDF embedded font (sfnt) at offset 0x11BA9 16792 bytes