Malicious PDF — malware analysis report

Static analysis result for SHA-256 17064d58be8f1bcf…

MALICIOUS

PDF

41.1 KB Created: 2021-03-31 18:11:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 21400a014bb841069cb0cacc85bdccf5 SHA-1: aafe7ae01a0cde311cc13d520bfc445b31295911 SHA-256: 17064d58be8f1bcf458a9350c1ed1f9051280ae627336c948e574c7a9bab6f37
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF is identified as a phishing lure due to its image-only nature and embedded clickable link. The document contains numerous external links, many of which point to PDF files, suggesting a link farm or redirection mechanism. The primary URL, https://dugedepap.ru/strik, is likely used to deliver a malicious payload or redirect to a phishing page.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9097

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 41 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/strik?utm_term=how+much+does+a+mechanic+earn+in+dubai
    • http://tulusujubige.mygamesonline.org/77752374288.pdf
    • http://jozipuvuwuzaj.mywebcommunity.org/xasutov.pdf
    • http://kajejib.medianewsonline.com/ecologia_y_gestion_ambiental.pdf
    • https://cdn.sqhk.co/kixituvelil/nTNpg8u/best_ukulele_tuner_app_android.pdf
    • https://cdn.sqhk.co/lunilageruvu/fhhhjhh/fusionner_deux_sur_adobe_reader.pdf
    • http://leseweremizew.scienceontheweb.net/how_do_i_get_ij_scan_utility.pdf
    • https://cdn.sqhk.co/dedesonor/r0wljbh/fojer.pdf
    • https://cdn.sqhk.co/luzigagoguna/bHCrirk/hoverboard_surfers_game.pdf
    • http://xafopawiki.medianewsonline.com/3672716259.pdf
    • https://cdn.sqhk.co/fawabanof/gjHhmhc/simple_and_easy_modern_house_minecraft.pdf
    • http://pikufufunuti.scienceontheweb.net/52821428454.pdf
    • https://cdn.sqhk.co/sadirorig/e9jhd22/45251450148.pdf
    • https://cdn.sqhk.co/wozokagad/vejgqwd/89045150678.pdf
    • http://fukijuwevo.getenjoyment.net/charlie_and_the_chocolate_factory_musical_veruca_death.pdf
    • https://cdn.sqhk.co/dedesonor/Bjiicst/online_auctions_near_me_today.pdf
    • http://pikubub.onlinewebshop.net/bending_moment_experiment.pdf
    • https://4c6480a9-ccec-4c20-853c-cc48681c44ad.filesusr.com/ugd/935adc_e48047c968e44d14abec6737423e578f.pdf?index=true
    • https://b9eb3541-094c-4606-b101-17c2291fd6e1.filesusr.com/ugd/a18601_54b1470b3daa4b3d8ae3eb6b73347879.pdf?index=true
    • http://tikomiwewo.atwebpages.com/37456303577.pdf
    • http://gumizaxewa.atwebpages.com/vunewiduboji.pdf
    • http://bitujiduruv.myartsonline.com/kettering_sda_church_directory.pdf
    • http://bejanifezilo.atwebpages.com/nuduwojubomasunesuxata.pdf