Malicious PDF — malware analysis report

Static analysis result for SHA-256 cd7b7e0e821a5586…

MALICIOUS

PDF

155.8 KB Created: 2021-07-17 01:48:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 66968b439251b041c3b28c887a4af76a SHA-1: 260445caaee2d9d32487c23d16a91399e670b9dd SHA-256: cd7b7e0e821a55868595e7490c0eae8b63462f9c91ad09a68fa9331b0044d994
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains embedded URLs pointing to external sites, which are likely used to deliver malicious content or phish for credentials. Although no scripts were explicitly extracted, the PDF structure and embedded URIs suggest an attempt to redirect the user to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7778

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/gPkW7oTCsL0/square?utm_term=castle+in+the+sky+full+movie+eng+sub
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f1f21f382df77e28244829/1626468896149/normal_hand_x_ray.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee0064d6548a387fd6b6af/1626210404463/alpha_c_chiang_solution_manual_4th_edition_free_download.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e9483a320dbd0de28237bc/1625901114974/need_for_speed_rivals_ps4_2_player_split_screen.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f052fc8938672b22edbcff/1626362622025/difference_between_per_stirpes_and_per_capita.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e949943ba7d954d54759dc/1625901460278/vexadeferubivaf.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f0faf3b238236d2330dd95/1626405619732/43133345676.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f20613d2b59222dd1f6677/1626474003635/recent_general_knowledge.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f1f4ff921a1d542f35682c/1626469631834/vawudimamivuvodem.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ec848adbb514329faf41c3/1626113162286/22_60_house_plan_west_facing.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001d19c.bin
a676690f67c9359182630e249600060eab6ec531663d28eb33df790e703f9b89
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D19C 11104 bytes
font_01_sfnt_off0001eb5d.bin
397c2bc4331b01a1d458b540c6ea9872786e982ccba402973e681685371fb45a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1EB5D 18616 bytes
font_02_sfnt_off00021bad.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x21BAD 16792 bytes
font_03_sfnt_off000233bb.bin
dfa7a4485b803487c43c3f6a650b044709de89b42261c9b0fff4d48d47d8e69c
pdf-font-stream PDF embedded font (sfnt) at offset 0x233BB 14884 bytes