Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b326bd85451b28d…

MALICIOUS

PDF

118.6 KB Created: 2021-07-20 09:32:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 15657e5a96798fc23e05ee74f161d3d4 SHA-1: d36ec9f194b2dc31b7b252c36daf8b5d10fad6f8 SHA-256: 9b326bd85451b28d1c959e88c9523c7c50a2f72d2cf7801e2daca90111e9c82b
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file was detected by ClamAV as 'Pdf.Phishing.Trojan', indicating a malicious intent to phish users. The presence of embedded URLs, although many are marked as benign, suggests an attempt to redirect users to malicious sites. The PDF structure also shows signs of manipulation with duplicate object bodies, which can be used to hide malicious content.

Machine Learning

  • Nyx PDF Classifier clean score 0.1376

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/iCUEKX862tE/square?utm_term=john+francis+smallholdings+for+sale
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f639754742d44d706f701c/1626749301735/natremia_medical_term.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f6125ea22c811cd222c90f/1626739294531/the_price_of_flowers_textbook_question_answers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000170e8.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x170E8 16792 bytes
font_01_sfnt_off000188fa.bin
49beb2eced53076f4c80d73c17d0cf35dea915e244c1af102189553ad16d9540
pdf-font-stream PDF embedded font (sfnt) at offset 0x188FA 17404 bytes
font_02_sfnt_off0001b620.bin
575bd8e62a9b63718ee84cdd9942afd1042b42314346aec6a90fb2ba3e5c6052
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B620 10816 bytes