Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0e7020ea591bc4d…

MALICIOUS

PDF

82.8 KB Created: 2021-07-13 01:02:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 8ded0560e9888a43a4f85bf826859b60 SHA-1: 86943979a007dc70345adfd6be936b7cb5cd3641 SHA-256: c0e7020ea591bc4d705e0bdc695e0f3c464404679bb1de6f0485b6e733bc4353
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file was detected as malicious by ML classifiers and ClamAV, indicating it is likely a phishing or trojan delivery mechanism. The presence of embedded URLs suggests an attempt to redirect the user to malicious sites. No scripts were extracted, but the PDF structure and detections point towards exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8896

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/-7-cX3opz_8/square?utm_term=how+to+connect+blue+yeti+mic+to+iphone
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e869c80ad3a627070f05f0/1625844168874/49069084457.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e93f1ce6a58043b692933c/1625898780838/pazupanijoroliwajut.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e879e774000c7cf29effbb/1625848295345/how_to_play_multiplayer_on_black_ops_3_xbox_360_offline.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e906d13b7e7c63344f2ad4/1625884369277/83734196629.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60eca8a3704a383bbedd2c1f/1626122406034/tiremesorelumufogenebe.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ecb878f9f3f24b30c5c796/1626126456396/pamerigudinaj.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e92ea12c5c2f6215c97402/1625894561783/negates_the_need.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e214.bin
39b7607dd88561c35cfa4a94697be166c492c0728c6d7e11250e6feb9b8cf47c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE214 17160 bytes
font_01_sfnt_off00010f21.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F21 16792 bytes
font_02_sfnt_off00012738.bin
36d28f9db75f638b4eadbf54beefa9f2a5bed5f5db4b884983e3cd457d9b7001
pdf-font-stream PDF embedded font (sfnt) at offset 0x12738 10640 bytes