Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a6282482f6a0063…

MALICIOUS

PDF

91.1 KB Created: 2021-07-14 05:43:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: ea0f580e2c18c727f1de0f4bab8b52e1 SHA-1: ad0a10bc948b950f07fd4e1a05fd3a6e9f3f607b SHA-256: 9a6282482f6a0063b54041f26d28434e48f50d0e30c54607ae7b17d39ac29d13
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by a machine learning classifier and ClamAV as malicious. It contains embedded URIs that point to external resources, likely for phishing or malware distribution. The presence of these external links suggests an attempt to redirect the user to a malicious site, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9809

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/iXsW93xxTQA/square?utm_term=words+and+expressions+class+9+solutions+unit+1+pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee4441f72ce0266e1045a4/1626227777644/47144325235.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec7ef83f7a034ccb7a29be/1626111736521/muster_the_will.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e7a91ed93aeb546a119eb0/1625794846667/extrinsic_meaning_in_english.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee40207d49fb55d6279e83/1626226720814/guxajaxefasimofipagu.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e7f01d8f757b1ac45275cb/1625813021941/89215281817.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ee09142d09e34b729c1c36/1626212628452/reverse_in_uno_with_three_players.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e90059e6a58043b6902b1b/1625882713952/31925184349.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ed1174e255175820bcda2f/1626149236784/22_ounces_equals_how_many_cups.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e7931f4b964f05b843e360/1625789215751/isabelle_dances_into_the_spotlight.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e899.bin
466dea703835b4b0fb16b0d745e8aa26a4587ffdf4bcd1e901bbadbaa0ade2f9
pdf-font-stream PDF embedded font (sfnt) at offset 0xE899 11028 bytes
font_01_sfnt_off0001026d.bin
fcca37035df06e555c2991ff65faa0e8497ca6423bee408ebc46b3aef925b516
pdf-font-stream PDF embedded font (sfnt) at offset 0x1026D 16144 bytes
font_02_sfnt_off000117e8.bin
c71a90d1d8de69724508f7c0cc51e413de414cd12a4544159fa4ac6e94aec544
pdf-font-stream PDF embedded font (sfnt) at offset 0x117E8 17392 bytes
font_03_sfnt_off00014572.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x14572 16792 bytes