Malicious PDF — malware analysis report

Static analysis result for SHA-256 b35867b793a58358…

MALICIOUS

PDF

134.9 KB Created: 2021-07-17 23:10:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 28d9ebdf5c247447d43a54897c297e8a SHA-1: 6aaa410d1ac9a504d4f8dd2ad33702c146117520 SHA-256: b35867b793a58358ede8b7adc9c507ffba7f0cd6c75f7d94bcbc7cae0abdfff3
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier, indicating malicious intent. The 'SE_INVOICE_LURE' heuristic suggests the document's content is designed to trick users into clicking embedded links, likely for phishing or malware delivery. Although no scripts were explicitly extracted, the presence of embedded URLs and the invoice lure strongly suggest an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9941

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/AG-UZpNbJGc/square?utm_term=occupancy+hotel+meaning
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f32849e615ea111e679044/1626548297752/adjectives_examples_sentences.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e9292dc91b61347ea40407/1625893166112/abscess_tooth_treatment.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f0a94e247c7e0f0264a2b8/1626384718803/fogovul.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ec7ab15f604029b990985b/1626110642277/how_to_write_a_dbq_in_45_minutes.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ee676f8e3fff2bd3c3142f/1626236784056/wow_classic_chest_3_stats.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ee809e588fb56695183f17/1626243230820/indian_history_terminology.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee90d7c27d1e40a54ece43/1626247383937/xutamowiwejunifexezexu.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec7b8c288cf71862a8c3fb/1626110860426/duo_factor_authentication.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f2f5466c177f33d79dd0c9/1626535238483/mikafevifafovegisijudori.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ee3f95e7148d06bc7111fe/1626226581409/solution_of_chemistry_class_10_icse_selina.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001aea3.bin
ef0e3ac89180a5dcc8f04d55278cc63020e52ddf9b11d55cf2ecac4cae57e9f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AEA3 17588 bytes
font_01_sfnt_off0001dcea.bin
3ba1aeb82f09ebb80c19abdddbb13b236342c2544d491e96943e664282052c54
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DCEA 10792 bytes
font_02_sfnt_off0001f5a1.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1F5A1 16792 bytes