Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2351367385f5cd4…

MALICIOUS

PDF

79.6 KB Created: 2021-07-16 02:23:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: ab45a82f667cc5bc70c85f21115caa8e SHA-1: 0de057518bee63de82723f4ce5fd59be897950f2 SHA-256: f2351367385f5cd40b567e8b9d0b56d99bfd7a82906abd841185d077cc358093
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing an embedded URL that points to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also flagged this PDF as malicious. While no scripts were explicitly extracted, the presence of an external URI and the overall detection suggest a phishing or malware distribution attempt, likely delivered as an attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8571

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://philabc.ru/square?utm_term=apa+7th+edition+in+text+citation+3+authors
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ee70023753dc428c8b4338/1626238978770/34806324431.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e8d206598de22e33d26e1a/1625870854713/1_irr_to_usd.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e8fab218245d33f18022ce/1625881266371/puzzling_questions_with_answers.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f0b9ac6e32095df97d568d/1626388908707/tafon.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f0ab9b28eedc473db45af7/1626385307578/attack_your_own_base_clash_of_clans.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e7ea527d3b385c94b63a9d/1625811538951/gta_vice_city_for_android_free_download_apk_data_highly_compressed.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d3f5.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3F5 16792 bytes
font_01_sfnt_off0000ec07.bin
13723496b87b965d916b51f92132e268508cec1748318b4dba425e147d8e2d29
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC07 17196 bytes
font_02_sfnt_off000118ff.bin
5be3db48eafb7818149f7da29778fb9447b49c87dd55998938498445b87e10c2
pdf-font-stream PDF embedded font (sfnt) at offset 0x118FF 10968 bytes