Malicious PDF — malware analysis report

Static analysis result for SHA-256 033543039069df3a…

MALICIOUS

PDF

75.0 KB Created: 2021-04-06 02:16:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b3d516d829cc57893b1d645a770836fa SHA-1: ba3023c8d46e1a2336b449de6a48d00b256d720d SHA-256: 033543039069df3ae36cd383a76e16ae48191fc22ffc2d8014e360e434a6036d
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document is identified as malicious by ClamAV and an ML classifier, exhibiting characteristics of a phishing lure. It contains an image-based lure and numerous external links, suggesting it is designed to redirect users to malicious websites or download further malware. The PDF structure and embedded links indicate a likely attempt to exploit users through deceptive content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6025

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 75 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/strik?utm_term=senco+nail+gun+repair+baton+rouge
    • https://karozazosepi.weebly.com/uploads/1/3/4/3/134316788/1376118.pdf
    • https://taferirufip.weebly.com/uploads/1/3/4/5/134582969/4d3120.pdf
    • https://cdn.sqhk.co/daxutoxod/QehiPjj/93768301105.pdf
    • https://cdn.sqhk.co/pipezifiwip/C4kmgds/10450628170.pdf
    • https://cdn.sqhk.co/bitomasijelo/Y3oib6c/butterfinger_ice_cream_recipe_with_chocolate_milk.pdf
    • https://cdn.sqhk.co/xejudawadoni/aighhid/fruit_cake_simple_fruit_cake_recipe_with_candied.pdf
    • http://krokoboko6.xyz/37456247m5iu.pdf
    • https://cdn.sqhk.co/zumumolebajo/HVifhg6/how_to_get_free_wifi_at_home_app.pdf
    • https://cdn.sqhk.co/suwinodujeja/6oqjjtK/biodata_writing_sample.pdf
    • https://xevibobi.weebly.com/uploads/1/3/4/6/134683071/71b79f5a58.pdf
    • https://xukexepizebeb.weebly.com/uploads/1/3/4/5/134592509/pokoxob_duturaf_vodufeviduzomap_fasabafeje.pdf
    • https://cdn.sqhk.co/novitovikor/RgdcpW8/john_gba_full_apk.pdf
    • https://rebazizezasij.weebly.com/uploads/1/3/4/5/134586802/zefanetotomobizovoso.pdf
    • http://hookup666.site/semanekimepopivajibuvipepg1bko.pdf
    • https://50e0a74f-e7a5-4ac3-a7a6-4cdd7b1ad00e.filesusr.com/ugd/8a9d9f_e9ba349dbf4c47dfac7242b70526a457.pdf?index=true
    • http://xurorovesi.epizy.com/49931248809.pdf
    • https://4bf641bf-117a-4913-931f-55e49063997f.filesusr.com/ugd/5befcb_cdc58ad86d684e608402879fb600908a.pdf?index=true
    • https://e0ff2378-281a-4ea3-95ae-419c526fdc99.filesusr.com/ugd/0baf77_2ba7e164774b45ae967360e2f7f71b64.pdf?index=true
    • https://438e95ed-c264-4db5-88d3-1a9ca8b91b86.filesusr.com/ugd/733c1f_c7c81c4611a14ab3952687562f3cda1e.pdf?index=true
    • https://4a39c6c9-989b-4d11-b2d8-cc0becc7f193.filesusr.com/ugd/ef0078_4a8b8544334146fd94c3212f83eb4236.pdf?index=true
    • http://jepugati.epizy.com/27227845589.pdf