Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6ffe7aeb5a44003…

MALICIOUS

PDF

74.7 KB Created: 2021-07-15 22:25:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 341c41f90877546911edda6a848c8a6c SHA-1: 549a11451fa5bb1a2fc6bfe1544eeef1e29c50eb SHA-256: a6ffe7aeb5a44003433e83f4a909c8208436524e237420d408a38d81b8b6e9c6
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a 'Pdf.Phishing.Trojan' signature. It contains an embedded URL that, while currently flagged as benign, is indicative of a phishing or malware distribution attempt. The PDF structure and the presence of an external URI heuristic further support this. No scripts were extracted, limiting the analysis of specific execution methods.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.2593

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/qI_NY8u86tA/square?utm_term=griller+for+fish
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e8ca08351081123f7c2c6e/1625868808300/kovanadabikal.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f00e97fd683a7867cafdf0/1626345111967/biographical_form_g_325a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c7f4.bin
310480be6dedd1e0dbd4c598b593f7f9c44a3df5398e58fc81fdfa58b3f3f69d
pdf-font-stream PDF embedded font (sfnt) at offset 0xC7F4 16224 bytes
font_01_sfnt_off0000f12d.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF12D 16792 bytes
font_02_sfnt_off00010943.bin
497238a129ca8d4ad12a9acaf54ac62497ae4e67bcf49135fc414c78614a51d6
pdf-font-stream PDF embedded font (sfnt) at offset 0x10943 9984 bytes