Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b7988e562aff737…

MALICIOUS

PDF

76.7 KB Created: 2021-07-13 16:33:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 63a15de32ea6fdfd866652d29993e3b1 SHA-1: b0d5765530132b212395c55f6b660f60da60e9b9 SHA-256: 9b7988e562aff7375209b572d3db9e159da343655593dfa4bdf629dc69b321b4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ML classifier and ClamAV detection strongly indicate malicious intent. The PDF contains embedded URLs that, while many are marked as benign, suggest an attempt to redirect the user to external content. The presence of PDF-specific heuristics like PDF_URI and EMBEDDED_URL points to the document's role in delivering or facilitating access to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/hIkXU_AiHkM/square?utm_term=i+love+to+praise+him+and+lift+up+his+holy+name+lyrics
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ec8cb6f6fc466b5bf3b834/1626115254588/how_to_save_a_document_as_on_mac.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e8ea9e58c6623f037f4d52/1625877150776/how_to_remove_side_comments_in_word.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e87b2aefdda0135911d808/1625848618810/75352987779.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec7c87c217102653d571c5/1626111112062/suicide_squad_2_tamil_dubbed_movie_download_in_isaimini.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ece6b7b1b13d3c3c0a7321/1626138295816/90_degree_angle_counterclockwise.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e869f379e5ad2408b2572f/1625844211628/paper_towns_page_count.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ed64161c817c33f6d624ef/1626170390221/17518458831.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e80c2725441e1b3787dc75/1625820199655/83855358818.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e7f5657d3b385c94b6997a/1625814373152/rupuviledaz.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e7e070ed7e630439644ff9/1625809008722/urdu_meaning_of_courage.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e82ec57be683581ce5d382/1625829061870/the_capital_asset_pricing_model_asserts_that_the_expected_return.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c75e.bin
766446ddc9b173cccca7ea5f18e7ca82b5b950545ee1c933169df15dee39b940
pdf-font-stream PDF embedded font (sfnt) at offset 0xC75E 17124 bytes
font_01_sfnt_off0000f405.bin
fa13aeec622397457b446f3c091c91aab15d53c98c2d75767781013ebbed7e1f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF405 11116 bytes
font_02_sfnt_off00010dd4.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DD4 16792 bytes