Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2cb16eee7d24445…

MALICIOUS

PDF

81.7 KB Created: 2021-05-14 17:35:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 8dd71551d11f9d8459d010ea3acf14fa SHA-1: ca402928c1acfc1f028f2c22f5617bb38bda3b53 SHA-256: f2cb16eee7d244453581124a3a3d7cbd5ada4d4e74f2755700299728db154e1b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF with a high ML score and ClamAV detection, indicating malicious intent. It contains an embedded URI pointing to 'baarspo.ru', which is likely a phishing or malware distribution site. The document body, though heavily obfuscated, suggests a lure related to vehicle information, potentially to trick users into clicking the malicious link. No scripts were extracted, but the presence of external URIs and the overall detection profile strongly suggest a phishing or downloader attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/strik?utm_term=toyota+camry+2018+le+oil PDF link annotation
    • http://hookup153.fun/youtube_mp3_converter2w5ri.pdfIn PDF document text
    • http://homiak.fun/qari_binyameen_abid_taqreer_3gp3a0ou.pdfIn PDF document text
    • http://datiwufirul.medianewsonline.com/alp_all_answer_key.pdfIn PDF document text
    • http://study-english-04.space/bumumijlr7r.pdfIn PDF document text
    • http://zifixoribe.scienceontheweb.net/betapo.pdfIn PDF document text
    • http://7lessons.space/dobawonanawidaxopezovi8koyx.pdfIn PDF document text
    • http://ritegifufefut.scienceontheweb.net/8th_habit_from_effectiveness_to_greatness.pdfIn PDF document text
    • http://secret-empire.ru/binary_addition_and_subtraction_examples81h1f.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://giwigevo.rf.gd/cbre_data_center_report.pdfIn PDF document text
    • http://bogibil.rf.gd/police_vehicle_inspection_checklist.pdfIn PDF document text
    • https://s3.amazonaws.com/mexavofezoxi/what_does_error_code_51030_mean_on_the_wii.pdfIn PDF document text
    • https://s3.amazonaws.com/mujevubutukoxu/57143501410.pdfIn PDF document text
    • http://tafoboverel.epizy.com/rulunise.pdfIn PDF document text
    • http://pitalipe.epizy.com/free_calendar_template_2020.pdfIn PDF document text
    • https://s3.amazonaws.com/zifilobesumafi/24717711044.pdfIn PDF document text
    • http://mifinuxob.epizy.com/rekotazizimesukodev.pdfIn PDF document text
    • https://s3.amazonaws.com/kudowo/givewenemitotofu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b6379cae-284e-4820-b4cd-deb6bb252d16/is_being_a_field_artillery_officer_dangerous.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/57a714f1-cda2-42ca-84bc-c9b2d9049f43/math_workbook_grade_3.pdfIn PDF document text
    • https://s3.amazonaws.com/dazawojob/african_history_book.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a4fbc8b-ef80-480d-ac3c-9c67fe5c1f7d/14643742393.pdfIn PDF document text
    • https://s3.amazonaws.com/rezugekolaba/silica_is_polar_or_nonpolar.pdfIn PDF document text
    • https://s3.amazonaws.com/poresi/diagrama_de_equilibrio_de_fases_de_un_componente.pdfIn PDF document text
    • http://nejarisiwudu.atwebpages.com/how_to_clean_keurig_2.0_water_filter.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f222.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF222 5020 bytes
SHA-256: 70b50bb75048d33520a51f321987868ef61888a9fbe84506d812bbb87bf7f7ed
font_01_sfnt_off00010337.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10337 11628 bytes
SHA-256: 3fa8f81e671550e2d3df724881dc25400d9a3c62e1936e52d572e72183446344
font_02_sfnt_off00012b0d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12B0D 4324 bytes
SHA-256: 1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361