Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5b781a6e2f930dd…

MALICIOUS

PDF

75.9 KB Created: 2021-07-14 05:09:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 0981f374da5d71b46720fe42d94a3eb4 SHA-1: cac66919b58743d3cef04bb6d19797ccea5e8f17 SHA-256: e5b781a6e2f930dd7b072231191bebed4bc16b1a403344f27e9c93c841ba5fb4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ML classifiers and ClamAV, indicating it is a phishing or trojan PDF. The presence of embedded URLs suggests an attempt to redirect the user to malicious sites. Although no scripts were explicitly extracted, the PDF structure and heuristic firings point towards a malicious document, likely employing techniques to trick users into visiting external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7390

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/4aHNpQc2m6I/square?utm_term=emotion+oriented+coping
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e7d5e8b977dd1475c9eb85/1625806312751/89416584255.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ee233c7c5bce1f334b02ae/1626219324894/77193806549.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ed4c380124a666ff427897/1626164280563/pijokowosuduju.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee3678fc191471fc6beec4/1626224248310/pilupepowefimixazu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c8fd.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC8FD 16792 bytes
font_01_sfnt_off0000e10f.bin
b8c47ad371a86257a488c7e81f3e93f5a1e7a0153f01217cac1a97c252f8fcd1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE10F 16688 bytes
font_02_sfnt_off00010c8a.bin
18ce432a59ef5a912680c18d64a2359076334e5269f55102b924750ffaf9ecff
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C8A 10464 bytes