Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4d14dfea470f2b4…

MALICIOUS

PDF

82.8 KB Created: 2021-07-22 04:20:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 829927a2f405a03f86732ef2a1516007 SHA-1: 97dfbf747bb3184883362fe8e435d80a62f6b757 SHA-256: e4d14dfea470f2b47306526a3b64d7079d26c6d905657c4bba42f7bbb8cbbbd4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a Google feedproxy URL, which is often used to obscure the final destination. While the document body is heavily obfuscated and unreadable, the presence of the malicious classification and the embedded URI strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/-7-cX3opz_8/square?utm_term=let+me+introduce+myself+my+name
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f4058826c2747482e6715c/1626604936858/65041183040.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f06887a05bd62f13dc520d/1626368135405/bimigifapum.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ed9ef23d37cd087e6cc45b/1626185458663/foxovanavetotuzurubujad.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f47bf7aba5f52989b51be7/1626635255257/zafuxaluweremujedikunewi.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60edcb3b0229956bd1324472/1626196795419/adversary_meaning_in_telugu.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f758b42b23a12a0ac1300c/1626822836831/kegivefapokedol.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f877ccc70f8844264d5591/1626896333059/strongman_stone_weight.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec903ca1b53f2c225ea575/1626116156905/perarelog.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f6d3e87d1af06e687d5326/1626788840180/93219668149.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ec88b6dbb514329fafaaa0/1626114231063/forasorenozobizena.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60f11e6f4be5f74a98e04d93/1626414703306/madufiwajekosetuv.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ecedd0937216722044ae8b/1626140112519/the_space_dance_centre.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ed85efbc85f73bac28e663/1626179055637/93317578485.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f2f945e615ea111e65181e/1626536261341/please_acknowledge_the_receipt_of_the_same.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f2c2247e0b4d5f6b140560/1626522148580/11723306447.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f28d26668793736d28c8be/1626508582882/52061432111.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e832361873c46ac93d1d23/1625829942173/woxasurofelefaxexi.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f279b404a1d9701792dd38/1626503604339/nugobuw.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e9332783ae0c490239b13a/1625895719905/mibidumes.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f4f31626c2747482f36d96/1626665750698/ft_lbs_to_inch_pounds.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f37343cba7b71501e82fbb/1626567492087/the_testament_of_sister_new_devil_episode_1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e160.bin
3e13476e8fb192ab1726040e6c4d8b06af7c8473a9e4bf83928d2e8342b7a136
pdf-font-stream PDF embedded font (sfnt) at offset 0xE160 16652 bytes
font_01_sfnt_off00010ccd.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10CCD 16792 bytes
font_02_sfnt_off000124e4.bin
691fe089a4f424390b7e61a61855fd80c278cdb8bd205814807bd8d904351e3a
pdf-font-stream PDF embedded font (sfnt) at offset 0x124E4 10808 bytes