Malicious PDF — malware analysis report

Static analysis result for SHA-256 e6d9b1297c9a54a1…

MALICIOUS

PDF

75.0 KB Created: 2021-07-19 05:52:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 1e9c1cc016eff5a79520a21348424171 SHA-1: 0c51c134f2080a33ae20f55a76c5377c7181435a SHA-256: e6d9b1297c9a54a1917b1b7e8a68d8d509e39f3c8285ccbdea9644492dea2f97
96 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The file was identified as malicious by both ML classification and ClamAV, with a specific detection signature indicating it is a Pdf.Phishing.Trojan. The presence of embedded URLs and the nature of the heuristics suggest it is designed to trick users or exploit vulnerabilities. No scripts were extracted, limiting the analysis of its specific execution method.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7788

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/X6hrLWyzjlw/square?utm_term=ikm+questions+and+answers
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f37cc7db752c5e49adad81/1626569927381/how_many_years_did_it_take_to_build_the_palace_of_versailles.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f4c03122602c08ca008247/1626652721827/raxijudepivowane.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f16e60311eab0d81aee721/1626435168935/jasprit_singh_semiconductor_devices.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c384.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC384 16792 bytes
font_01_sfnt_off0000db9b.bin
57641e9d090e058a9b84501058bea4bf733263066e35ab42d89f7261e2a5b16f
pdf-font-stream PDF embedded font (sfnt) at offset 0xDB9B 10736 bytes
font_02_sfnt_off0000f421.bin
ddb48d7633fb63cdbe982fda67f1bac8b4c461cc52f580c5b47d8138b8220b3b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF421 17032 bytes