Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e17af71bf5c591c…

MALICIOUS

PDF

77.4 KB Created: 2021-07-20 16:31:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: ca5a86db7524fd1108069aff2d5ee33e SHA-1: baccd7efdb20a966fae202df5b97f49b1c60255c SHA-256: 9e17af71bf5c591cea1d71b6924a5ca51f602689a745b53bfa20cdf1069d168e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs and the 'wkhtmltopdf' authoring application suggest it may be used in phishing campaigns or to deliver secondary payloads. Although no scripts were explicitly extracted, the PDF structure and heuristic firings point towards exploitation or redirection techniques.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7390

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/UQ8tT55rDuk/square?utm_term=painful+hiccups+after+eating
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60edd1c59779423221de6621/1626198469777/84191156984.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e81c4a872c4c6263c75989/1625824330753/308th_judicial_district_court.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f6c7481f75e014b6e11e87/1626785608869/latifa.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f5ff3d7953d835fbdea369/1626734397761/meselson_and_stahl_experiment_notes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d02f.bin
51cdb5768e3c8accd85fcdfa13982874112c76cc19c0ed5af651b69fe427bf43
pdf-font-stream PDF embedded font (sfnt) at offset 0xD02F 16228 bytes
font_01_sfnt_off0000fa41.bin
522281d8c28b29552c25c877f50071c46dc47f50d4b2228861aa8ab828d92487
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA41 10740 bytes
font_02_sfnt_off000112e2.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x112E2 16792 bytes