Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac3f5c58fcb53e4f…

MALICIOUS

PDF

78.0 KB Created: 2021-07-15 19:26:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 918b78c3eea8c08c15a9a6985e7cbe9f SHA-1: 01ef279a3ff12c32709ca020a5bdad3f50b147d3 SHA-256: ac3f5c58fcb53e4f92abffec9711a3d36c8f7878b3699f0d55329c8e020e5fb6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF was flagged by ML classification and ClamAV as malicious, strongly suggesting it is designed for exploitation or malware delivery. The presence of an external URI, although labeled benign, indicates potential for further malicious activity. The document body is heavily obfuscated, preventing a detailed analysis of its specific lure or payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9906

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/EjZ5HCEZs_A/square?utm_term=happy+birthday+mom+in+different+fonts
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e79b006e46386ca3bcdb91/1625791232256/92645022434.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e8ff7e19a9f87deb716a89/1625882494676/91284904381.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec704c950202184f0e94eb/1626107980321/northeastern_commencement_2021.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ecb0f9635fe735bd7ea821/1626124537895/anny_and_robert.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec8d3eb3b63f0898f28fa5/1626115390430/58386758585.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee44e933d4654651bdeeed/1626227945170/what_does_mos_stand_for.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e822bf9ebc0053f3196d8b/1625825983804/horticulture_book_download.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60efda05bba06d2f34171bef/1626331653453/nezomoxales.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60f017984980ba6b3b6fbd4b/1626347416684/xexivotoxikilisevemaba.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d202.bin
8ca5593f02a261931c478699b86bddbda84d910298b5917fbced84cb4a0826fc
pdf-font-stream PDF embedded font (sfnt) at offset 0xD202 10964 bytes
font_01_sfnt_off0000eb07.bin
2c8c41004455922663bb4b2c0b9b899b55027ba4e258c6b12ea68132eba2cd25
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB07 15852 bytes
font_02_sfnt_off000113d1.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x113D1 16792 bytes