Malicious PDF — malware analysis report

Static analysis result for SHA-256 eab609be64dca175…

MALICIOUS

PDF

85.9 KB Created: 2021-07-17 03:00:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 908d90d156de50213fa5b07cfb51188d SHA-1: e8486e2f7c244ae44bcd35cd2b9afa898b3c6fae SHA-256: eab609be64dca175f49d5cdff6e50731d6c2793d2b73cb06bd3236e8af13f959
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs, despite some being marked as benign, suggests an attempt to redirect the user to potentially harmful content. The PDF structure and embedded artifacts are consistent with a phishing or malware delivery mechanism, likely involving JavaScript execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/pL_UGxDroB4/square?utm_term=sample+of+appraisal+comments+for+employees
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ed4e6739532c3941bf4dc4/1626164840034/jajironaremol.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e8d63f78606b4d185755db/1625871935193/how_the_brain_learns.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e9448ae370ac63228a0bc2/1625900171076/confused_meaning_in_bengali.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60efe48779f953043cbd538f/1626334343830/types_of_angels_and_their_roles.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ed9091b8016c0d1ad838a9/1626181777440/tajenibazugenopelun.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f052fc8938672b22edbcff/1626362622025/difference_between_per_stirpes_and_per_capita.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e78b0351cb2a526cf814ec/1625787139807/if_i_have_to_live_my_life_without_you_near_me.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ec7a5f700aa07a7893df56/1626110559364/the_hobbit_2_full_movie_download.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f2077e54ceab78eed207fd/1626474366174/cha_cha_answers_number.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eeee.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEEE 16792 bytes
font_01_sfnt_off00010700.bin
3f2ba5787a5501670e6fd0c177103c8b3f628b7851e1b53b6433eae3e8950b1b
pdf-font-stream PDF embedded font (sfnt) at offset 0x10700 16224 bytes
font_02_sfnt_off000130cb.bin
b3f3de8cf37d7ca7d1d317a4df6965ea5a526c69da3e38cf0738a6bf561d8e84
pdf-font-stream PDF embedded font (sfnt) at offset 0x130CB 10828 bytes