Malicious PDF — malware analysis report

Static analysis result for SHA-256 cd77ff7a458100fa…

MALICIOUS

PDF

84.2 KB Created: 2021-07-16 17:58:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: da0ef9fcdd815f2a93f7c81942b16737 SHA-1: 17fce3f41ac7c5e22d794835dc145804954941c4 SHA-256: cd77ff7a458100fae6df354892873657dda1380027195afd02c3534b6ec54b2a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing an embedded URL that points to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also strongly indicated maliciousness. While no scripts were explicitly extracted, the presence of an external URI and the overall detection profile suggest a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9987

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pistant.ru/square?utm_term=cfo+scale+up
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ec78f7288cf71862a8789b/1626110199791/30885673182.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ee35504d490f6727514b0a/1626223952389/dizoku.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ee905ca005482cc15acd5d/1626247261126/miles_between_two_addresses.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e8cb57614165378940927e/1625869143738/31143260191.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ec8ca390a3fc495319e098/1626115235742/gixukabigovozodixufe.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f15e59c825a553dff73e62/1626431065857/8374360638.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f0c681d1fa142bceaabe46/1626392193479/john_rawls_theory_of_justice_download.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec88c4947cc46ca129257c/1626114244600/25531915048.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f0af47173c2b6f1e599f0e/1626386247434/rizejisipaxo.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60f0b7b22606b657d3506d2d/1626388402107/nibawof.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60eddfe6670c344ea75d3e8e/1626202086230/70232093635.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee25f739b8260338687701/1626220023857/44878859787.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e935.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE935 16792 bytes
font_01_sfnt_off00010147.bin
3ba6d3b146edf2f2379ee152379d3393d2b1c256c3e116c7ebb40ffc52a5e2aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x10147 17112 bytes
font_02_sfnt_off00012e03.bin
d1dca189afac769c91b407757e5d59ef9b11144f544fa418b51a40d21424aeb5
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E03 10212 bytes