Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4f9d18b75ae8b33…

MALICIOUS

PDF

74.9 KB Created: 2021-02-28 01:11:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: f13c0943fe790de53bac63f3b4a0d3c6 SHA-1: dad3edc19c4948d2e726982ddb31056e15b0937d SHA-256: b4f9d18b75ae8b33ac858ca0bc985fdc9370b50f01c17d2cd41e2d0c790b0d50
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier, indicating malicious intent. The document body, though heavily obfuscated, contains references to 'Poulan chainsaw 18 inch carburetor' and an embedded URL pointing to 'gimoguvi.ru', suggesting a phishing or malware distribution lure. The presence of embedded URLs and the nature of the detection strongly suggest a spearphishing attachment attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/strik?utm_term=poulan+chainsaw+18+inch+carburetor PDF link annotation
    • http://rodsfish.club/tugafovupevikadeel9qk.pdfIn PDF document text
    • http://vbruti.site/jowovagola9sy.pdfIn PDF document text
    • http://distornyup.site/gmat_study_material_2020blidj.pdfIn PDF document text
    • http://myshoes.moscow/fenisesunajofateneb41cv.pdfIn PDF document text
    • https://cdn.sqhk.co/texekikevow/8ijgjji/218271358.pdfIn PDF document text
    • http://paganel.world/voxawabavarexurs3r1l.pdfIn PDF document text
    • https://cdn.sqhk.co/gubisagebuto/BWid6kD/best_portable_music_player_2020_uk.pdfIn PDF document text
    • https://cdn.sqhk.co/bawijodol/Aoibqls/space_pinball_classic_game_apk.pdfIn PDF document text
    • http://stnold.com/crazy_driver_taxi_duty_3d_mod_apk_revdlwo32p.pdfIn PDF document text
    • https://cdn.sqhk.co/wefegiwezon/ji2N7mo/cultist_base_slayer_gate_locked.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/davolazupivowi/96083994777.pdfIn PDF document text
    • https://s3.amazonaws.com/jixerubowi/50747053009.pdfIn PDF document text
    • https://s3.amazonaws.com/lowuwofuxali/asma_scielo.pdfIn PDF document text
    • https://s3.amazonaws.com/widiku/troy_bilt_riding_mower_turns_over_but_wont_start.pdfIn PDF document text
    • https://s3.amazonaws.com/jaxesabi/pidobogodawavokemizidibag.pdfIn PDF document text
    • https://s3.amazonaws.com/wemupajese/business_card_template_psd_vistaprint.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e6bb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE6BB 5368 bytes
SHA-256: c4846290fb6d5dd702b24a385669e00e6b2bcabc0a3d3818fbabd9af6a6cb559
font_01_sfnt_off0000f90e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF90E 11212 bytes
SHA-256: c2a621b9ffc2ec223cc90e74685d4c47f05f17d799690d133142448503c8d6aa