Malicious PDF — malware analysis report

Static analysis result for SHA-256 a61ec87fa2455ab2…

MALICIOUS

PDF

143.1 KB Created: 2021-07-12 22:11:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 6c75bab261ea66f9c9ce6ab18e2b6c22 SHA-1: 3fda2746c6517b4f72439028b4195a0bc480f14a SHA-256: a61ec87fa2455ab2ec25bac6ed8993029840eddf92dfd66b0523834b0780aff1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded URLs, despite some being marked as benign, suggests an attempt to redirect the user to external content. The PDF structure and heuristics indicate it is likely a phishing or malware distribution lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5261

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/mHcMeCcfVl0/square?utm_term=g+codes+in+cnc+programming+pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e87c7d163d09390fd8f2e0/1625848957480/how_do_i_add_screen_record_on_my_iphone.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e8c13409230f0e1841e65b/1625866548394/kuxotubexaveregam.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e926328ce0e10532d2e151/1625892402768/mixafalododojos.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ec83afbdd82073f6ff1270/1626112943107/89216055529.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ec818a82b4c978cf416deb/1626112394850/tedox.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001d06f.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D06F 16792 bytes
font_01_sfnt_off0001e886.bin
17bb70c13ed0e6288f756b87c1b2504e148de845dfcc73d6e5add7d7884530c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E886 10860 bytes
font_02_sfnt_off00020155.bin
e1c5fed5c5e3116db3b88fb6918aaf55ca744ec28c2978b892d0b5b574ebf55f
pdf-font-stream PDF embedded font (sfnt) at offset 0x20155 17848 bytes