Malicious PDF — malware analysis report

Static analysis result for SHA-256 baadb8862e0e3ecb…

MALICIOUS

PDF

72.9 KB Created: 2021-07-16 13:08:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-08-25
MD5: d9ab417398ffc93e527d2e4d3dc89b79 SHA-1: 3e6de9f3c65ef88b4f576059cbcd441c2ec05d5e SHA-256: baadb8862e0e3ecb6172ed04e7dcd50e8678d50710e8ec302fef4d14b4442091
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file was detected by ClamAV as Pdf.Phishing.Trojan, indicating a malicious intent. Heuristics identified embedded URLs, suggesting the document may attempt to redirect the user to malicious sites or download further payloads. The presence of duplicate objects in the PDF structure could be an obfuscation technique.

Machine Learning

  • Nyx PDF Classifier clean score 0.1797

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/7R6buoffwiA/square?utm_term=pavilion+in+the+park+pikesville PDF link annotation
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f0cf665422dc4ac5c11676/1626394470965/the_shining_in_theaters.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60efdfc5c57e07264c1fb2d6/1626333125326/wapamemukasoxagefed.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bef5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBEF5 10508 bytes
SHA-256: fda199053ac27514df5bac23d6c4abae96b7b27ba909e62f1cc99ad62a10578c
font_01_sfnt_off0000d6d2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD6D2 15964 bytes
SHA-256: bbf962bf1bbc8a1d4d989bd6cd4d13eeb81510071a0faf5d276ffa9dc286f5dd
font_02_sfnt_off0000ffe8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFFE8 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1