Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab0a14605d3fb538…

MALICIOUS

PDF

106.1 KB Created: 2021-04-03 15:19:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a1534498f88418359e8bbc853369d7fe SHA-1: d2bd8b4cb1349872d21c06c0541ec7c15b66f29e SHA-256: ab0a14605d3fb53843e7ee3606c0a6c77fee698b00befa098f1fe4e76beebe99
144 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF document flagged by ML classifiers and ClamAV as malicious. Heuristics indicate it uses an urgency lure and an advance-fee scam lure, suggesting a phishing or fraud attempt. The document contains an embedded URI pointing to 'gimoguvi.ru', which is likely the malicious payload delivery or phishing site. No scripts were extracted, but the PDF structure itself is indicative of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/wix?keyword=muffin+time+full+song+roblox+id
    • https://cdn.sqhk.co/zopizote/juUdcNS/tajurapiboj.pdf
    • https://cdn.sqhk.co/wovedajuraki/o2hbidf/neck_pain_check_upper_left_side.pdf
    • http://gomivewikikuwu.22web.org/99919546543.pdf
    • http://medesutaduj.22web.org/fastest_android_web_browser_2019.pdf
    • http://vemajewedekag.22web.org/appropriate_prepositions_with_examples.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/399f31fb-3030-4135-80c5-03fff94eb5d5/28967609365.pdf
    • https://s3.amazonaws.com/laradusa/formule_de_calcul_de_l_absentisme.pdf
    • https://s3.amazonaws.com/tutapaxi/electrical_maintenance_job_description.pdf
    • http://fawivemepogu.epizy.com/rpf_constable_2018_answer_key_group_d.pdf
    • http://lojogonofar.rf.gd/mokenewuvasomuzi.pdf
    • https://s3.amazonaws.com/vuforewebub/posovimavamiw.pdf
    • https://uploads.strikinglycdn.com/files/5099ea77-9797-4d22-b803-04438a792c37/21083020640.pdf
    • https://s3.amazonaws.com/wixatax/80436306834.pdf
    • https://uploads.strikinglycdn.com/files/252d730b-46d2-4c7a-83fc-71519af3d7db/programa_para_hacer_ejercicios_de_estadstica.pdf
    • http://koravas.rf.gd/anopheles_life_cycle.pdf
    • https://uploads.strikinglycdn.com/files/45d04364-e0c9-43d6-b272-32a01924a61a/super_vpn_free_vpn_client_pro_apk.pdf
    • https://s3.amazonaws.com/semuxemakaw/house_of_commons_guide_to_laying_papers.pdf
    • http://deroselewem.epizy.com/jomonagajizidod.pdf
    • https://s3.amazonaws.com/ragejufa/likipemoponatosizub.pdf
    • http://xozelabudizi.epizy.com/answers_to_riddles_in_squirrel_nutkin.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014f0d.bin
ff4f2f2d12ffb835e068def791419f6f6f707611a4dfa4d5a1d9ca8299dd268c
pdf-font-stream PDF embedded font (sfnt) at offset 0x14F0D 5112 bytes
font_01_sfnt_off00016063.bin
2199628833abfe2a090d0f7803df61f69e6c85d5ed23962fd7efb00e3c33313a
pdf-font-stream PDF embedded font (sfnt) at offset 0x16063 13180 bytes
font_02_sfnt_off00018c9f.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x18C9F 4324 bytes