Malicious PDF — malware analysis report

Static analysis result for SHA-256 f281900c635c8107…

MALICIOUS

PDF

128.0 KB Created: 2021-07-12 21:20:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-08-20
MD5: 5c24d04d27130ef8a2352293b5848018 SHA-1: faca2677d9b71e88346ece9cf67dd24d0d8aeb92 SHA-256: f281900c635c8107bd5e301c08cf720d4ebeb42644fd2c05cc6a4dbdc2833f99
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as a phishing trojan by ClamAV. It contains embedded URLs that likely lead to malicious content or further stages of an attack. Although no scripts were explicitly extracted, the presence of embedded URLs and the ClamAV detection strongly suggest a phishing or social engineering attempt, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4554

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/AnJPYMJXbyQ/square?utm_term=inside+listening+and+speaking+1+answer+key PDF link annotation
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e85a20402b2441d131fce6/1625840161083/meloranibejubano.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e949a83f195e1e40378f1d/1625901480725/nofewetupotunewerewevip.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e868d1565c2358bf0ffecf/1625843921708/17325277611.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e80ef85eabb22f35dcb071/1625820921065/good_budget_apps_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019421.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19421 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0001ac33.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1AC33 17224 bytes
SHA-256: d041a497b07e1f04fa96bc68851095c4516ee1e9c580e4ba2b5e81fa6f681d13
font_02_sfnt_off0001d943.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D943 10744 bytes
SHA-256: 89caa709ad94d4ba186c688114c2d803808b52731b67c191cc0e0b88055f519b