Malicious PDF — malware analysis report

Static analysis result for SHA-256 b8ebe3025eafa6a2…

MALICIOUS

PDF

79.7 KB Created: 2021-07-13 23:40:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: dc57c2d6e98e87b03b0b136443694d1b SHA-1: ce3148ab644af75e100e91c1c26ee57fa31b067f SHA-256: b8ebe3025eafa6a235c04e4b9ce25068ee7f9749a54844ef703a1dc23a55cb7d
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ClamAV heuristic identified this PDF as 'Pdf.Phishing.Trojan', indicating a phishing or trojanized document. The presence of embedded URLs, even those initially flagged as benign, suggests an attempt to redirect the user to malicious content. The document body, though heavily obfuscated, likely contains the lure text. The PDF structure and embedded artifacts are consistent with malicious PDF documents designed to exploit vulnerabilities or redirect users.

Machine Learning

  • Nyx PDF Classifier clean score 0.1467

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/4Ji06Fp1PxY/square?utm_term=cottage+grove+oregon+air+quality
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e79b27a3609a707ba8905c/1625791271659/how_to_check_if_instagram_account_is_private.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e7c2fafdc75e32ab066563/1625801466809/signs_of_temporal_arteritis.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d727.bin
9c681159c3d578298aebc17ff2e06a908db9efd3526dc1028296d91b3fd83c03
pdf-font-stream PDF embedded font (sfnt) at offset 0xD727 10572 bytes
font_01_sfnt_off0000ef2d.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF2D 16792 bytes
font_02_sfnt_off0001073f.bin
f040da09fbc3b4d5824701391a0c67b7fad09d21071ba38b8580dc1b39549dfa
pdf-font-stream PDF embedded font (sfnt) at offset 0x1073F 17116 bytes