Malicious PDF — malware analysis report

Static analysis result for SHA-256 b85a6853feda7a5c…

MALICIOUS

PDF

74.0 KB Created: 2021-07-13 03:12:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: e87003b60e2a28ea27dda63d673ea810 SHA-1: f77ef21ccbfb756596a7d8610057f563a03e79e0 SHA-256: b85a6853feda7a5ceaf88abcdbee1ec141e74730e2f575f9436b80a87f08e4f5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded URLs and the PDF structure suggest it's likely used as a phishing lure or to download further malicious content. Although no scripts were explicitly extracted, the PDF format itself can contain executable JavaScript, which is often used for obfuscation and payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7703

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/HbdJGeoIq_s/square?utm_term=an+endoscope+is+a
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e795ea23621b4743e017fc/1625789930201/mistborn_rpg_review.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e92739320dbd0de281447f/1625892665101/use_edification_in_a_sentence.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec80a2b8cbe518df57785d/1626112163075/security_and_its_types.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c393.bin
4333a34a501fc0cac8b7ffbc3b8700db491e7b01849b9bc11d5b832d8af2aa18
pdf-font-stream PDF embedded font (sfnt) at offset 0xC393 16248 bytes
font_01_sfnt_off0000ed94.bin
8304b8b57fb7f70f06f98357634e994b7f90b92b8473e3928d9f58efc87a1c5c
pdf-font-stream PDF embedded font (sfnt) at offset 0xED94 10244 bytes
font_02_sfnt_off000104b6.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x104B6 16792 bytes