Malicious PDF — malware analysis report

Static analysis result for SHA-256 daea9a2a92fc63d4…

MALICIOUS

PDF

79.5 KB Created: 2021-07-18 20:24:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: a014aff5bffb6c5c0b0be60f508df5bf SHA-1: cef640259071ad082181da16f7924d47277ff861 SHA-256: daea9a2a92fc63d446feaccead8eadf60d2e937cd2c0e02e383c4a22e2541380
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged by ML classifiers and ClamAV as malicious, exhibiting characteristics of an advance-fee scam. The document's structure and embedded URLs suggest it is intended to deceive users into believing they are receiving a prize or parcel, a common lure for financial fraud. While no scripts were explicitly extracted, the PDF format itself can embed JavaScript for malicious actions, and the presence of external URIs indicates potential redirection or payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8439

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/ZV5PD9BTPXI/square?utm_term=the+invention+of+hugo+cabret+by+brian+selznick+pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60eccbe6752fe37f0c0b92b3/1626131430380/best_motion_picture_oscars_2020.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f1c87458f881765a4c8687/1626458228957/88185054097.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f24d7b6d5e991e36d5c12c/1626492283223/55909779426.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec8c83e4ca3800a11856e1/1626115203638/95997678348.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8c65f09230f0e184245f8/1625867871454/the_battle_cats_story_of_legends.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d2f9.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD2F9 16792 bytes
font_01_sfnt_off0000eb10.bin
62f3ab551069220fc2a53c093f5208cc3fc473bba61cfb564529049fc0025ede
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB10 11436 bytes
font_02_sfnt_off000105b0.bin
a4245d0994ae3365c8e174ba2186a4bc30da6b18ba88897b5286601e9dc731bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x105B0 17948 bytes