Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea1f3325513a6fb4…

MALICIOUS

PDF

81.0 KB Created: 2021-07-13 17:47:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 2ecc3ebdc1539c82bf700bb4e6656ba6 SHA-1: c26e193a6a616aed931eaf17adcf35d0d76940b8 SHA-256: ea1f3325513a6fb4b693fb0ef62d4efbac1a54e941adc4633a34aab4d698d172
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was flagged by a machine learning classifier and ClamAV as malicious, with heuristics indicating the presence of external URIs. Although no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it is designed to lure users to malicious content, likely for phishing or malware delivery. The presence of multiple embedded URLs points towards a phishing attempt or a downloader.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9840

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/1LSSs5qy-i4/square?utm_term=slate+is+clean+meaning
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e8e0565ebba154a8f89870/1625874518252/levin_for_hillsdale.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ecef720689303983954510/1626140531018/71118459.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e93be4085b1c120f990aa2/1625897957026/iron_maiden_the_loneliness_of_the_long_distance_runner_lyrics.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e87cc87abd14085bc0187e/1625849032481/charitable_cash_contributions.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60eda14293ea6d7f6ef642a2/1626186051022/the_slope_of_speed_time_graph_gives.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ec86ec0d838b6c850d47d2/1626113773003/michel_foucault_society_must_be_defended.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ece349bde79631d3380427/1626137417825/spatial_meaning_in_marathi.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e94bf0f4fe78435a3c0535/1625902064834/dogogigedatuwatelagat.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e964c4566ded7d61ae8fe4/1625908420176/sample_size_determination_formula_for_unknown_population.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c84a.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC84A 16792 bytes
font_01_sfnt_off0000e061.bin
f7242a54487a6991953cad585d91647b4178c37933da4cc44d95da312fd34e23
pdf-font-stream PDF embedded font (sfnt) at offset 0xE061 10428 bytes
font_02_sfnt_off0000f7f5.bin
9d5144547e0b729630886a3ad3ce48e7da84b0115899dd9c2390406af6f0fecd
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7F5 16092 bytes
font_03_sfnt_off00010d36.bin
f19357b6a12933911af50705f953d1995452d3237cf98373bede44d8962132e9
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D36 16348 bytes