Malicious PDF — malware analysis report

Static analysis result for SHA-256 a54edf394b8360cc…

MALICIOUS

PDF

100.2 KB Created: 2021-07-13 04:56:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 8fc01c4c4745883089f13fa2e4860c27 SHA-1: 9171486e79346a57dca9582ce393c5d4a01e7da0 SHA-256: a54edf394b8360cce8881008689bda6ccd306a012ce5671c6c495b596fa0be67
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was flagged by a machine learning classifier and ClamAV as malicious, indicating it is likely a phishing or trojan delivery mechanism. The presence of embedded URLs, though many are marked as benign, suggests an attempt to redirect the user to malicious content or download further stages. The document body is heavily obfuscated and unreadable, preventing a more detailed analysis of its specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7883

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/4Ji06Fp1PxY/square?utm_term=letter+to+a+lost+best+friend
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec9131934d360eb2896109/1626116401214/nikefazakijexeten.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ecd24f752fe37f0c0c0fbf/1626133071920/small_drawings_on_hand.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e8af4a71f6484fc4147bbd/1625861962902/template_for_tuition_advertisement.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ecbb12635fe735bd7f98ce/1626127122382/selenium_quiz_questions_and_answers.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e960c32c5c2f6215cad192/1625907395902/memosadoka.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ec7a2831b0b43e07e5dc02/1626110504675/another_word_for_trick.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012ad7.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12AD7 16792 bytes
font_01_sfnt_off000142e9.bin
51ee6fadecba96a0717ffbed4effbe2058d6e2e63bd2a10ac0ea2febdd1d9803
pdf-font-stream PDF embedded font (sfnt) at offset 0x142E9 16332 bytes
font_02_sfnt_off00016d23.bin
c099b0130cc2cf5cfe51ac43691c822bd658dc232deed03351763a3cad600a76
pdf-font-stream PDF embedded font (sfnt) at offset 0x16D23 10444 bytes