Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b410a1bc74dd903…

MALICIOUS

PDF

79.9 KB Created: 2021-07-20 00:27:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 50a1a097521a4abe28ba048eed3aca2c SHA-1: b1855ab35693e8f2be4ea72c8bc69931f9369e74 SHA-256: 8b410a1bc74dd903ae8068a3cbfa8b11ee3a991649d0dac9fdaa1f723303d827
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by ML classifiers and ClamAV as malicious, indicating a phishing attempt. The embedded URLs, although many are marked benign, suggest an attempt to redirect the user to malicious content. No scripts were extracted, but the presence of embedded URLs and the overall detection by security tools points to a malicious document designed to trick users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9906

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/5JeRQhMeIYg/square?utm_term=how+many+play+cards
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec7e48668ba31612b5815a/1626111560616/70051630572.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f5edbfbb22fe09a2b33fa4/1626729919379/what_is_defamation_of_character.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8bef51102953de5821a25/1625865973944/converter_powerpoint_to.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e88c7d18d2642310524850/1625853053397/zanalizifi.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec7de16ad76c09748f9eca/1626111458031/paxizid.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f076b71a769948b7533655/1626371767934/subekadijub.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f5c7341a4e121640f8f272/1626720052118/rulosozewoka.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ee40d5a005482cc156a357/1626226902079/todedoxulotolanikasos.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ec82eff89f8e700bf753fc/1626112751744/essential_grammar_in_use_download_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d834.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD834 16792 bytes
font_01_sfnt_off0000f04b.bin
30140eb7799e4dbe0975095d26f6ffc0fcd3505d67ff114baf77af031b94f276
pdf-font-stream PDF embedded font (sfnt) at offset 0xF04B 10544 bytes
font_02_sfnt_off0001084c.bin
ce55fcfa301ab50ac533c9b358e56463c245bfcbde20f8035230d407c11d5740
pdf-font-stream PDF embedded font (sfnt) at offset 0x1084C 16660 bytes