Malicious PDF — malware analysis report

Static analysis result for SHA-256 856f20ebc92424af…

MALICIOUS

PDF

95.4 KB Created: 2021-07-14 02:15:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-08-25
MD5: 5f0c68cf3c8907058ff7946abaf3f373 SHA-1: b4c0e3f169018ebf7610d943799aa1b4829b23de SHA-256: 856f20ebc92424afa3bd01cc5f385de91187653287b5d6a99dab9935200fa770
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. Heuristics indicate the presence of an external URI and an image lure linking to an SEO redirector, consistent with phishing attempts. Although no executable scripts were extracted, the PDF structure and heuristic firings suggest it is designed to lead the user to a malicious external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9820

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/gPkW7oTCsL0/square?utm_term=double+integration+method+cantilever+beam PDF link annotation
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e8983552e7db6e70a30151/1625856053909/north_south_east_west_online.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec9a3abc6eee4b05903ca8/1626118714144/31712035711.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e932da3ba7d954d546c4c2/1625895642333/camp_kinser_commissary.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e7a19b7d3b385c94b28d9c/1625792923616/60722343474.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee16a5df3d323292cd9c3b/1626216101382/blocked_numbers_on_my_phone.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e93ac0db8bb141bada35e5/1625897664553/xatefujibakefunijotuvel.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e7804b6169212f0820c8e6/1625784395400/closed_end_mutual_funds.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e7cf314261ba7980609f0f/1625804593884/vosili.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e94d97f492d21a0f6c3a57/1625902488195/intestate_succession_by_state.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb05.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFB05 18568 bytes
SHA-256: aef54569af579c3e972dd801110c3aeceae54f6aed1acf227ad0234bf61d5cb4
font_01_sfnt_off000129e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x129E6 16168 bytes
SHA-256: 1cfb00680a8a18ef5d5af493cc5b57cfe410abeba37087ee2ecd799c98b61e68
font_02_sfnt_off00013f83.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13F83 10956 bytes
SHA-256: 07665945ec96c7b292ecf088ef5120513e7966b4967336f065d206f2a769de0b
font_03_sfnt_off0001587f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1587F 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1