Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dd94db760b23e5c…

MALICIOUS

PDF

74.7 KB Created: 2021-07-14 08:06:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: a457cc4f58dc53d3d3406f9f49801492 SHA-1: 4fe953cf9cefd1dcf77a0de260779e27c27d78d7 SHA-256: 9dd94db760b23e5c824577652a412dcbe91d113a5fd8988cf185b675092d1cd8
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a 'Pdf.Phishing.Trojan' signature. It contains an embedded external URI pointing to 'https://garglob.ru/square?utm_term=100+ounces+of+water+is+how+many+cups', which is a strong indicator of a phishing or malware distribution attempt. The PDF structure itself does not contain readable content, but the presence of the external URL and the ClamAV detection strongly suggest malicious intent.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.2687

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://garglob.ru/square?utm_term=100+ounces+of+water+is+how+many+cups
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ed8d92c439f8287166d896/1626181010348/besujuseniligezodexepaset.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e94a850cbdad4d35070a37/1625901702032/ruzewagejijam.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c18e.bin
283460970864ebcd954675820c1539184d848f4bb8c4ba9c13ac31484421139d
pdf-font-stream PDF embedded font (sfnt) at offset 0xC18E 11076 bytes
font_01_sfnt_off0000db54.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xDB54 16792 bytes
font_02_sfnt_off0000f366.bin
4c21849023c2d5e05c4da22556005f5830f6b3a0b7a771dd3b15ded189630070
pdf-font-stream PDF embedded font (sfnt) at offset 0xF366 16660 bytes