Malicious PDF — malware analysis report

Static analysis result for SHA-256 a4d303b40ae3e44c…

MALICIOUS

PDF

71.5 KB Created: 2021-07-19 20:02:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: f9a3eb8022e507131a4482c1486ada06 SHA-1: e103c9a0ca9d6fd1a3348cca11a5b2c6800b7bd4 SHA-256: a4d303b40ae3e44c7fa033c64e8565bae0fae681ca05a1ce63eb08dad863932f
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature Pdf.Phishing.Trojan. The embedded URL, while flagged as benign by the reputation service, is present in the PDF's metadata, suggesting a phishing attempt. No scripts were extracted, limiting further analysis of the attack vector.

Machine Learning

  • Nyx PDF Classifier clean score 0.2209

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/UkUWPC8UKDU/square?utm_term=understanding+nutrition+12th+edition+pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e9489518245d33f182ede3/1625901205164/after_buddhas_death.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e9006cf4fe78435a393b4a/1625882732505/apostrophes_are_used_for.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b835.bin
417e22a85f8ead7677142632f273c2b4b499e76718cb04e2303c354ab13ac087
pdf-font-stream PDF embedded font (sfnt) at offset 0xB835 11008 bytes
font_01_sfnt_off0000d1a1.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD1A1 16792 bytes
font_02_sfnt_off0000e9b3.bin
e001dc97df5a086dd5c3377b6052a30f93005f27f67eb56565a135b2af43790c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9B3 15708 bytes