Malicious PDF — malware analysis report

Static analysis result for SHA-256 89a73ec1b611e0cd…

MALICIOUS

PDF

93.1 KB Created: 2021-07-14 02:20:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 84574450ace0e319767785549a1167ca SHA-1: aedd346f1adc5f0d84537ecece20f4318daad74a SHA-256: 89a73ec1b611e0cd3894e3c8effb500ce72231c59270ab4a991d88a40ca9fb37
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was flagged as malicious by both ML classification and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs, though many are confirmed benign, suggests an attempt to lure the user to external resources. The file's structure and detection names point towards a phishing or trojan delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8172

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/NsX9ihectO0/square?utm_term=claim+of+fact+value+policy
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e9231ac22c005c9338b742/1625891610948/how_to_write_interval_notation_on_webassign.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e96710c0906550d90d2823/1625909008731/subramanian_swamy_books_download.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e81188fdc75e32ab09baaf/1625821577087/homologation_in_english.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ed7a29c2b47a6141a3b787/1626176041909/wujarabofonafilafod.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee0cb0796bb0196c5dc601/1626213552370/a_room_of_ones_own_notes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010d1e.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D1E 16792 bytes
font_01_sfnt_off00012535.bin
ec31d2ac9e37ba80d93caed4caa79c2b7f1beb8f68066ceaf86cbf77a142ca3a
pdf-font-stream PDF embedded font (sfnt) at offset 0x12535 10580 bytes
font_02_sfnt_off00013d6e.bin
9c75bb0b40ad4de4fd84a6c0c8ca2267821b43e18e0063d0d71e70953909d3f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D6E 16240 bytes