Malicious PDF — malware analysis report

Static analysis result for SHA-256 880da00e7e68e38d…

MALICIOUS

PDF

64.6 KB Created: 2021-02-23 00:04:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 043119bb173b5436f73cc3fce5647403 SHA-1: 2dbb688f5865424cac30b54dc985968d9b6c395e SHA-256: 880da00e7e68e38d160265f61e18ec82ea87476fed8155b047362e4cc8d3f6cb
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains numerous embedded URLs, with one prominent URL pointing to 'baarspo.ru', suggesting a phishing or malware distribution attempt. The 'PDF_SEO_DISPOSABLE_LINK_FARM' heuristic further supports this, indicating the PDF is part of a link farm on disposable hosting, a common tactic for distributing malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/strik?utm_term=2019+lexus+rx+350+suv+for+sale PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4473359/normal_5fcb3937f1a14.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4455390/normal_5ff772edd94e7.pdfIn PDF document text
    • http://dobewobezusisof.iblogger.org/west_iceland_travel_guide.pdfIn PDF document text
    • http://kinoogf.space/fitipubabuc3wr8.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4449170/normal_5ff94cd16f592.pdfIn PDF document text
    • http://bestgirl69.com/poxavupuguzexuxafubupus6uuuu.pdfIn PDF document text
    • http://fubesewokelo.22web.org/new_zealand_clinical_guidelines_for_stroke_management.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420250/normal_603113fdb5962.pdfIn PDF document text
    • http://azorocheat6.xyz/gilera_runner_50_manualc79to.pdfIn PDF document text
    • http://kind-insta.site/25667112372dwcfe.pdfIn PDF document text
    • http://niwapona.iblogger.org/dubufokafazuluwa.pdfIn PDF document text
    • http://pogadai.xyz/bujos8fqyr.pdfIn PDF document text
    • http://garant-ritual.online/toro_awd_22_personal_pace_mower_reviewsl5ewr.pdfIn PDF document text
    • http://yyyyyyhhhhh.space/mawuxakjyia.pdfIn PDF document text
    • http://kakerusejom.iblogger.org/crm_icons_free.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jivamubug/avengers_endgame_post_credits_scene.pdfIn PDF document text
    • http://gamupuzif.epizy.com/beronibivavivemaj.pdfIn PDF document text
    • https://s3.amazonaws.com/xidazeze/bleacher_report_live_roku_app.pdfIn PDF document text
    • http://siletafelit.epizy.com/how_do_you_reset_the_oil_light_on_a_2007_honda_civic.pdfIn PDF document text
    • https://s3.amazonaws.com/jifedefujodu/7596925248.pdfIn PDF document text
    • https://s3.amazonaws.com/pewebopufupe/sofogutofopalufozasobajag.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bf87.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBF87 5564 bytes
SHA-256: 173c83a76304739d16ad281395f54742f35b8e7885c48c7f0a171aa754e4562a
font_01_sfnt_off0000d28d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD28D 10080 bytes
SHA-256: be9373d1f54c8aad709258131b23759b03da62c612d59c2ceaccc6a0f822c593