Malicious PDF — malware analysis report

Static analysis result for SHA-256 73ef6cfcd216d4ce…

MALICIOUS

PDF

64.1 KB Created: 2021-02-20 12:40:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dff48e530b0c906838a046d572b8c0b8 SHA-1: 1e9e0c7bb32eb4949195eaa343e14a6b905480a4 SHA-256: 73ef6cfcd216d4ce98a59906b4557018cf378b47426a82d3a3746444ddd1b916
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many of which point to file-hosting services and appear to be part of a link farm designed to mimic search results for academic papers. The primary URL, 'https://baarspo.ru/wix?keyword=electricity+and+magnetism+purcell+2nd+edition+solutions+pdf', suggests a lure related to educational materials. The presence of multiple Weebly and other file-hosting links indicates an attempt to distribute further content, likely malicious, under the guise of providing requested documents. The ClamAV detection and ML classifier strongly support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/wix?keyword=electricity+and+magnetism+purcell+2nd+edition+solutions+pdf
    • https://vituxusupodewe.weebly.com/uploads/1/3/1/3/131379836/85606048143a32d.pdf
    • https://cdn-cms.f-static.net/uploads/4374699/normal_5fd384805ea18.pdf
    • https://pojojozujivalim.weebly.com/uploads/1/3/1/1/131164399/maxomatuwebijit-wirafidifo-pelakonevol.pdf
    • https://cdn-cms.f-static.net/uploads/4455198/normal_5fdbbd6bf1068.pdf
    • https://cdn.sqhk.co/vetukalujir/ijfSzhg/vikugusalazofobokaz.pdf
    • https://pusesame.weebly.com/uploads/1/3/4/6/134662227/giveduxuke-badawimodaze.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dotivaf/crystal_reports_tutorial_sap_b1.pdf
    • https://s3.amazonaws.com/vebenok/78915810566.pdf
    • https://s3.amazonaws.com/tujeviwakirawu/avast_secureline_vpn_full_free.pdf
    • https://s3.amazonaws.com/tawovojo/tigeser.pdf
    • https://s3.amazonaws.com/faxaxos/kenai_river_king_salmon_report.pdf
    • https://s3.amazonaws.com/sulasatevirexo/what_is_the_synonym_of_listless.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bd28.bin
0e5cca930f168e3c9e1d425d675ee729c508cf6ef643fc91a044a16cab8b8d0d
pdf-font-stream PDF embedded font (sfnt) at offset 0xBD28 5668 bytes
font_01_sfnt_off0000d076.bin
e5449970fe56a865ef85dd4fe683f5f8627b61d75014e2f509c67e56561e5e34
pdf-font-stream PDF embedded font (sfnt) at offset 0xD076 9960 bytes