Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7f732c830436cc9…

MALICIOUS

PDF

77.2 KB Created: 2021-07-17 03:17:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 3639f735ffd5389d0ac7a2293cb617e4 SHA-1: 4be0185196ccd9e4845fa652596e6559d589e8e0 SHA-256: e7f732c830436cc952a5f88613910a7361ed3d1017075c301bd5fe0d3c2af271
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious. It contains embedded URLs that likely lead to phishing content. Although no scripts were explicitly extracted, the presence of embedded URLs and the nature of the detection suggest it is designed to redirect users to malicious sites, potentially for credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/J-SxIuB37Ms/square?utm_term=the+science+of+fake+news+pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f2010f6ddefe7be86b5f7c/1626472720014/bagonisifutufesikejedun.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60eca83d0f7d8d50062f3f3b/1626122301431/90082790717.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee236c1f51426150cb455b/1626219372438/how_to_build_an_armor_stand.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f0fbf45554232196ba529c/1626405877102/gusufiruxul.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f00d260511021e70b5d686/1626344743214/tier_one_vocabulary_words.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f08b664d042f3c0b4f0dee/1626377062621/89163677754.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60edba86e8627508461daf92/1626192518675/youth_the_future_of_travel_ielts_reading_answers.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60edcfcd8e89d93564d367a6/1626197965670/figelamudomodedeko.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec92b70f7d8d50062cfec9/1626116792055/what_does_it_mean_by.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee8a24e9cbfe6c2fec1d4b/1626245668936/comprehensive_pharmacy_review_by_leon_shargel_free_download.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60edbe37ea8d40126a189b3d/1626193463280/character_sketch_of_prince_of_morocco.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ccaf.bin
6fdc3b0a2bb938a5c23763a360030b6aa74fb953eb0794d8d77ca43eec2139fb
pdf-font-stream PDF embedded font (sfnt) at offset 0xCCAF 16680 bytes
font_01_sfnt_off0000f839.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF839 16792 bytes
font_02_sfnt_off00011050.bin
575c66c38460cf5bd82e8355fcab56e1c199bf22aa0afd1bfbbbddb38cc1c3a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x11050 10616 bytes