Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5cec754079462fe…

MALICIOUS

PDF

74.4 KB Created: 2021-07-13 20:36:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: d91d01c53aa16d6ce5f084a699efdde5 SHA-1: afa6f0e93830fc5ab0e8ae67b6b7e06aa85f1a20 SHA-256: e5cec754079462feb071885f29e693308b53ac73e53006c5b895bf42573001da
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ClamAV heuristic identified this PDF as a phishing trojan. An external URI was found embedded in the PDF's metadata, pointing to a URL that, while currently marked as benign, is suspicious in this context. The PDF structure itself is also malformed, with duplicate object bodies, suggesting intentional obfuscation or an exploit attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.1751

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/r_nBws6J8g8/square?utm_term=php+current+date
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ed19d6493b43382089d47c/1626151382184/how_to_put_text_in_a_picture_in_word.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c550.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC550 16792 bytes
font_01_sfnt_off0000dd67.bin
24fb57177ebcf5969face127d8a470a7eff0d0168b81fa7cefbe3f248f07fe7a
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD67 10284 bytes
font_02_sfnt_off0000f472.bin
86774678adc4be1673d8467f6c7ef91e54e4c9e6135ca2ab1ebfea5f679c6205
pdf-font-stream PDF embedded font (sfnt) at offset 0xF472 16304 bytes