Malicious PDF — malware analysis report

Static analysis result for SHA-256 f77b54a97f9b5540…

MALICIOUS

PDF

97.4 KB Created: 2021-07-14 00:34:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 33fb467e17743aabbe270af01faecc30 SHA-1: b31d43fbe1afd3246080534769953315f39a8d3b SHA-256: f77b54a97f9b5540c191120c8b2ed1be8f742c71f2fb0742d7566b4bbed713e4
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample was identified as malicious by ML classifiers and ClamAV, exhibiting characteristics of an advance-fee scam. The document's content, though heavily obfuscated, suggests a lure involving a prize or beneficiary and parcel delivery requirements. While numerous URLs were extracted, they were all confirmed as benign, indicating they are likely decoys or unrelated to the malicious functionality.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8343

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/WVKuihPcy9U/square?utm_term=gumball+the+watch
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee0213e55429721e2503e5/1626210836173/not_belong_to_a_non_mendelian_law_of_inheritance.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee051e8443ee2c8934377e/1626211614328/printable_plant_cell_diagram.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e8d73a123eaa19f8fd1382/1625872187178/33140887592.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e8db30ea5a3748ec5cb7e2/1625873200649/87670533953.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60edfd3f0229956bd13789e2/1626209599839/example_of_formal_email_requesting_information.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec8fc8e0914637f38bd746/1626116041287/billy_crawford_and_mandy_moore.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011855.bin
926aff7d43f9b0179e73a02979738d857d78f0a9f28543f89280c8612fd7cc44
pdf-font-stream PDF embedded font (sfnt) at offset 0x11855 10276 bytes
font_01_sfnt_off00012f94.bin
e0a4c25661c249f37a89f6d31e715f8550be84537e521b087afa27203902f87d
pdf-font-stream PDF embedded font (sfnt) at offset 0x12F94 18544 bytes
font_02_sfnt_off00016057.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x16057 16792 bytes