Malicious PDF — malware analysis report

Static analysis result for SHA-256 f4126921f6ba6ded…

MALICIOUS

PDF

75.9 KB Created: 2021-07-16 09:35:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 81ea5f11245903219d72ad2685ded16a SHA-1: 8d415d3817834a843a39df1fb9ea2cda1f4b69ba SHA-256: f4126921f6ba6dedb550e590e43a05d9a1cfc5f2e2740a2575421c93988e6e95
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as a malicious PDF phishing trojan by ClamAV and an ML classifier. It contains multiple embedded URLs, some of which are marked as confirmed benign, but the overall detection indicates malicious intent. No scripts were extracted, but the PDF structure and embedded URIs suggest it is designed to lure users to malicious content, likely for phishing purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7703

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/razvivatel/yapz/~3/UZrB20b2Dcg/square?utm_term=how+to+drive+a+manual+car+in+traffic+pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee3bad2485902f3e733e22/1626225581664/sdg_health_and_wellbeing.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ee497be7148d06bc71c302/1626229115930/jomuxenagese.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee644eeed6cd77ab644c51/1626235982263/52916336516.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c907.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC907 16792 bytes
font_01_sfnt_off0000e11e.bin
7c6c928437ffed158b11e8bd5aec14c1bce5bda5afc7639b82a0c47e1eb690b3
pdf-font-stream PDF embedded font (sfnt) at offset 0xE11E 10856 bytes
font_02_sfnt_off0000fa25.bin
6c93459a45a9f2b12aac6f7c1fc74d99e33d1ee426469c2e3200777ef880b71f
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA25 16124 bytes