Malicious PDF — malware analysis report

Static analysis result for SHA-256 bffa693ec81c70d9…

MALICIOUS

PDF

90.3 KB Created: 2021-07-12 21:33:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 2517536101f557419f6421cde07f3df5 SHA-1: d6297c7c4efc2d7eb3db2b4cc8bbfa2d72c9ea08 SHA-256: bffa693ec81c70d9d9128579922c90d4f78477794f18f34f747558521347a076
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by a machine learning classifier and ClamAV as malicious. It contains embedded URLs that likely lead to malicious content or phishing sites. The presence of embedded URLs and the ML classification suggest an attempt to deliver a payload or phish users, aligning with the Spearphishing Attachment technique.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9896

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/UZrB20b2Dcg/square?utm_term=watch+love+%26+basketball+online+free
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e939218ce0e10532d366e3/1625897249778/jinigulepokas.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec88f5d0153e73bf8c6892/1626114293632/wusejer.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e7e915dbc52028c8401d7e/1625811222094/the_age_of_adaline_2.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ec86125978cb5ccaab1280/1626113554308/rikiba.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e818845eabb22f35dd0b4e/1625823364518/21460586826.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec84b7dcef4a49b3ab0384/1626113207783/mp4_3gp_video_download.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e8cf5a546fd16393e402ad/1625870170910/vacation_email_outlook.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec7722bdd82073f6fdc4b7/1626109730999/xened.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec858ec3fb560d26f312a4/1626113423157/sports_illustrated_swimsuit_2012.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010157.bin
01427dd6dbf4d47f4d53ea7a9a79cb3e360afc7da40ded98adbefe116b73afc9
pdf-font-stream PDF embedded font (sfnt) at offset 0x10157 17656 bytes
font_01_sfnt_off00012f43.bin
3ae413f9a3a461481ed484e8be11187cca7cc69be2b1443b3d61acce039efc23
pdf-font-stream PDF embedded font (sfnt) at offset 0x12F43 9920 bytes
font_02_sfnt_off00014568.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x14568 16792 bytes