Malicious PDF — malware analysis report

Static analysis result for SHA-256 d14cbd4146841857…

MALICIOUS

PDF

91.8 KB Created: 2021-07-18 15:47:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 1f85927b0b3e23b6713090a330d402be SHA-1: 9e6561772770c8d383fd5b2526a7a5d10fa90abb SHA-256: d14cbd4146841857d17ca19a9e9c9e0272b9358fb3a8060879000bce4c52b94e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded URLs, even those confirmed benign, suggests an attempt to lure the user to external resources. The file's structure and detection patterns align with known malicious PDF campaigns.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9897

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/X6hrLWyzjlw/square?utm_term=odd+degree+polynomial+has+real+root
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60efef4b34f25751eec157a3/1626337099974/geometric_sequence_formula_for_the_nth_term_calculator.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f2f893c2d40e67ec061b72/1626536083483/most_rare_knife_in_csgo.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ee908e588fb5669518ea70/1626247310360/5101694649.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec8a8cb6dedd3ae1698a5f/1626114700843/protection_one_alarm_manual_k3743.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e81690f4d7c53d8b159724/1625822864957/cam_and_c4_plants.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f255bbb84a576e6cf68bdd/1626494395553/definition_of_conveyance.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e8f1f23b7e7c63344e0cac/1625879026201/2658913694.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e85aa245407067ba695526/1625840290398/what_is_not_psychology.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f0096597dca740078dffe2/1626343781421/zukizepumibetude.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001041b.bin
e71fd049c092b9a0520a30d35aa6613bd9e4bce22d02f610da040a044e140ddd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1041B 17496 bytes
font_01_sfnt_off000131d8.bin
64ae0539f73b6f3d9bbb020ba29cf10961aac679bc48de154eb1ca519067c514
pdf-font-stream PDF embedded font (sfnt) at offset 0x131D8 10980 bytes
font_02_sfnt_off00014af1.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x14AF1 16792 bytes