Malicious PDF — malware analysis report

Static analysis result for SHA-256 fde400a3e87582a9…

MALICIOUS

PDF

84.3 KB Created: 2021-07-18 11:33:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 8ed758a04785e8d3767fb340770e2709 SHA-1: 0cea01a4a4512e529efb915c36cd4a7a7658bba0 SHA-256: fde400a3e87582a9c5d29352f216f970d7b6ccd23966678d38ae6fc99717a3d6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a malicious PDF detected by ClamAV and an ML classifier, indicating a phishing attempt. It contains multiple embedded URLs that likely lead to malicious content or further infection vectors. Although no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to external sites, potentially for credential harvesting or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8871

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/v-xubMviL4Y/square?utm_term=200+pounds+beauty+full+movie+malay+subtitles
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e7f2d023621b4743e4ec00/1625813712234/unit_10_sequences_and_series_homework_3_geometric_sequences_answers.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e9111d787dde1a90ad7de6/1625887005777/kixufodudunisiw.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e8ce843bde986563e45202/1625869956447/57539186018.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ec91fd7d354a5e86a41791/1626116605198/measurable_objectives_examples.pdf
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f1a5013386d078c70dc995/1626449153983/29082313522.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ee09237426fb5109f0d5d5/1626212643851/nuboxofodufapejija.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e84666ad723f3b6758fb35/1625835110547/pafopedilo.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f21be7abd24e3ae56f85de/1626479591415/13121730377.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d8fa.bin
5ac65d0f40157cfb7e07baa2ccb4722f5ca9ec816504e207050b71268709e0b5
pdf-font-stream PDF embedded font (sfnt) at offset 0xD8FA 17116 bytes
font_01_sfnt_off0001057f.bin
5eab8b0e03f17dc6a753f1df1c5193413f8fb453a46c69a816d89c7f8f14d594
pdf-font-stream PDF embedded font (sfnt) at offset 0x1057F 11124 bytes
font_02_sfnt_off00011f4e.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F4E 16792 bytes
font_03_sfnt_off0001375b.bin
62ac774c129779c5c18271cbf75f4192d90122d9b9f0081758bd35eaa2e4b4a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1375B 3160 bytes