Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d82e8cd90b20d78…

MALICIOUS

PDF

90.1 KB Created: 2021-07-17 18:27:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: e2dcc8042a889224e3b0c399aa2d2885 SHA-1: 6f20f1bad498edd51cd5fe43a34ae4726f5d3b2e SHA-256: 9d82e8cd90b20d783075bce1f722e231d5b2df169939959902a5bfa1eb38baff
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF with a high ML classifier score and ClamAV detection indicating it is malicious, specifically flagged as phishing. While the document body is heavily obfuscated and unreadable, the presence of an external URI heuristic points to a potential phishing lure. The embedded URLs, though marked as benign, are part of the PDF's structure and could be used to redirect users. The primary attack vector appears to be social engineering via a malicious document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/0YvHz_IItD0/square?utm_term=notes+for+human+reproduction+class+12
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ed9db850566b3f866617bd/1626185144881/53334342300.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ee44132af4c01978fd44fa/1626227731512/zuxinevimupurebobafaboxo.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60f0dc55b238236d232ef631/1626397781753/laying_someone_to_rest.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e95ca312fb7d0b279521b5/1625906339380/zikeretojipirejad.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f0c6654bb49071de13dc3c/1626392165400/rod_stewart_and_busker.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f00bf536870d1a2db7c81e/1626344437767/what_is_social_science_in_sociology.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f24f9722602c08cae5e4aa/1626492823364/michael_jordan_driven_from_within_download.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f2e3f01434f635471e520a/1626530800804/zufomowazerutok.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f21a7aba3f5603c3b852e2/1626479226577/begakokukojiweburif.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f2366d1db272198f8b689e/1626486381911/93496787174.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f186212c92ee1ddde1eac1/1626441250320/zinadopujeb.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e94bd3787dde1a90af553f/1625902035974/ziwiwisamarabuf.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f1b85397e302667f2a1e92/1626454099876/33687602910.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60f0b30a21e37b5b0f34192f/1626387210375/vowizavadetubi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ff45.bin
a8d3b6baf56f1beb4a449aa1c4c2099a72f9fcedec4385e1fa735ad1c4613a4a
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF45 16460 bytes
font_01_sfnt_off000129ea.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x129EA 16792 bytes
font_02_sfnt_off00014201.bin
d606a50c782a58cc4ae3674efe25cd5ca24e6444133e41558a57154f59d6610b
pdf-font-stream PDF embedded font (sfnt) at offset 0x14201 11132 bytes