Malicious PDF — malware analysis report

Static analysis result for SHA-256 a22d7b76c2c04b5e…

MALICIOUS

PDF

127.5 KB Created: 2021-07-13 16:19:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 9645abfd480fc047f613569d9499547a SHA-1: 765b9d5e93c49ee1f5220fba81b8ddfa2ebc9f44 SHA-256: a22d7b76c2c04b5ed8bd3d7a8d073217fbce43f8af407a5d0b921d450ec0ad61
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains multiple embedded URIs, suggesting an attempt to redirect the user to malicious sites. Although no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a phishing lure, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/NsX9ihectO0/square?utm_term=what+is+the+preamble+and+what+is+its+purpose
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ec7a2219a16f038d615ba7/1626110498919/the_hobbit_chapter_14_questions_and_answers.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ec9b2377250868136eef07/1626118947279/5844443573.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e8e20e66be7e490f0c5479/1625874958366/pezefalapikijikepone.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ed881c0318596fdcc4c38f/1626179612910/33639497063.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e95c5918245d33f18366e6/1625906265503/sakaxekevatutukezokov.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e7fa7a9bae382bbac0bb41/1625815675090/best_romantic_novels_of_all_time_free_download.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec76f42de9850677720d7c/1626109684593/74267792045.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e7c6ce51cb2a526cfba7da/1625802446869/when_is_jcpenneys_going_out_of_business.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec81258bb04542cee45df2/1626112293410/7th_pay_commission_recommendations.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019353.bin
11227926857d758465c954e03130879c948c5d998433c442845625b49f64287e
pdf-font-stream PDF embedded font (sfnt) at offset 0x19353 17584 bytes
font_01_sfnt_off0001c067.bin
eea6f052aa77f529a734af88a10f74f7afcd813a5d714b77247527816ac456d0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C067 10976 bytes
font_02_sfnt_off0001d97f.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D97F 16792 bytes