Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1d5d8df893f500c…

MALICIOUS

PDF

79.1 KB Created: 2021-07-18 20:46:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 9ca09c1bcd4243b10e17bc765af62451 SHA-1: 9970f8854c06f598de1771625fab2e631fd9b8ee SHA-256: c1d5d8df893f500cbb9bc7c357202f7ca190dd801e2741e185c24b3840b95e54
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains embedded URLs that likely lead to malicious content or phishing sites. Although no scripts were explicitly extracted, the PDF structure and embedded URIs suggest an attempt to trick the user into navigating to a compromised or malicious website, potentially for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9906

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/W5vEtEh6t-A/square?utm_term=cbse+class+12+biology+last+5+years+question+papers
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f19f2fa6070b670f050950/1626447663191/60369463818.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f00c2afd683a7867caead0/1626344490547/kiganubunoroxomeku.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f2b2301ad9bf1c32acd300/1626518064083/11447370154.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e8a08c082d905bfad8ffdf/1625858188952/text_structure_practice.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f1ccb656286c59025d55e3/1626459318580/48984205437.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ec8cf97a6a162676493ad6/1626115321333/auguste_dupin_stories.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ec8d5705183b3b579df8c4/1626115415379/paraphrase_of_the_poem.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e8f24c025aa46e30d0b528/1625879116834/logufisuximoxubodu.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee069d172ba47bdac80855/1626211997876/louise_gluck_odyssey_poems.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d15e.bin
62b0d97cb20b5c74e932d65632c69f10bf4e97eae74da84ddb96445b008535db
pdf-font-stream PDF embedded font (sfnt) at offset 0xD15E 11388 bytes
font_01_sfnt_off0000ec05.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC05 16792 bytes
font_02_sfnt_off00010417.bin
5ac1690e82656fbe1fa78f2d8a1915801fc695d3cabd87fabb8bee92b7de1a52
pdf-font-stream PDF embedded font (sfnt) at offset 0x10417 16876 bytes