Malicious PDF — malware analysis report

Static analysis result for SHA-256 c270415604e8b0d1…

MALICIOUS

PDF

87.1 KB Created: 2021-07-22 03:23:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: c5e2779aa5a50e4fdab5b55ab4eb801c SHA-1: b17c47131c5ccbac0781c50a310f93ad00b1135f SHA-256: c270415604e8b0d19893ccebc142a9b110e2ff2c1418204bebb5fb212d75e067
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF that contains an embedded URL, flagged by heuristics as potentially malicious. ClamAV detection and ML classification strongly indicate malicious intent. While the document body is heavily obfuscated and unreadable, the presence of an external URI suggests an attempt to redirect the user to a harmful resource, likely for phishing or to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/UZrB20b2Dcg/square?utm_term=song+i+get+by+with+a+little+help+from+my+friends
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f8ac99d0dad67a22d4da60/1626909849752/dojovalupewanowikaka.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f835659b8d893641e3205f/1626879333912/dinesh_companion_chemistry_class_11_free_download.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f4d17aec5ad00cc0a146d7/1626657147145/autobiography_of_great_leaders.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f4fcf050974615f935fbc0/1626668272533/81321084905.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f653edbd95132ca7282966/1626756077786/20409004212.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e86e7fe0b7df382a7f1380/1625845375381/33641393221.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f08a558424ee64a06d394f/1626376789439/ridarafivun.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec8ef469d4b6336147cfe5/1626115828248/sajukupulunojumoko.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f8a7437f728b6ca904c9e4/1626908483882/business_studies_class_12_chapter_5_organising_notes.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec8bcc19a16f038d6350fb/1626115021008/how_do_i_increase_oxygen_in_my_blood.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f8b477c368992324fac0be/1626911863678/97610522201.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f0bfc3b238236d232d1650/1626390467361/tikavo.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f62811d62802464e3b7ae6/1626744849874/mizan.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e7ec4628bb5f4f51642429/1625812038656/majomogupe.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f89842e4dd7f06555f539f/1626904642603/stad_in_die_mis_questions_and_answers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f01c.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF01C 16792 bytes
font_01_sfnt_off0001082e.bin
59f73a27cb1609ee64525c2e4132dfe410f96e9bfcf4ae6a1f323dc1d4a949c7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1082E 17100 bytes
font_02_sfnt_off000134e8.bin
ee3cc42f78861fe540701b66210fe0aea9e6bba118ac2698e6d3d19108e08ef1
pdf-font-stream PDF embedded font (sfnt) at offset 0x134E8 11360 bytes