Malicious PDF — malware analysis report

Static analysis result for SHA-256 1db8fd6d3f51ecc7…

MALICIOUS

PDF

59.7 KB Created: 2021-03-29 20:03:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 4d835d633be8b34c60957069b7c87165 SHA-1: eeafb2886ec736e3016eea965ade5dd117679b04 SHA-256: 1db8fd6d3f51ecc718a99069b4ff60534d35eaa53e3f7283a4a246240e5dfb12
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5491

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/award?keyword=materi+kuliah+akuntansi+keperilakuan+pdf PDF link annotation
    • http://xozonline.ru/angular_6_formgroup_submitnvxqs.pdfIn PDF document text
    • http://tafuxasomup.getenjoyment.net/the_minto_pyramid_principle.pdfIn PDF document text
    • https://dikekivex.weebly.com/uploads/1/3/0/7/130775400/jurofibas.pdfIn PDF document text
    • https://cdn.sqhk.co/jimumakevaji/jdhiqii/the_lighthouse_of_alexandria.pdfIn PDF document text
    • http://dusikazo.mypressonline.com/sitowekuwopikifov.pdfIn PDF document text
    • https://butijewib.weebly.com/uploads/1/3/4/8/134886415/6361a1ebfa2.pdfIn PDF document text
    • https://cdn.sqhk.co/rularijulen/chah8gj/46912655456.pdfIn PDF document text
    • https://fufuwotasivixi.weebly.com/uploads/1/3/5/9/135966690/gutivisi-mevinev-loruja-jofaxujijol.pdfIn PDF document text
    • https://tozikogok.weebly.com/uploads/1/3/5/3/135330875/400529.pdfIn PDF document text
    • http://pebifakonek.sportsontheweb.net/wemubaketifiveninudo.pdfIn PDF document text
    • http://upgrade4me.com/conspiracy_the_trial_of_the_chicago_8_streamingojuka.pdfIn PDF document text
    • https://cdn.sqhk.co/pixorikibam/biiB5jh/argentine_football_managers_in_europe.pdfIn PDF document text
    • https://cdn.sqhk.co/kizajituxab/6ggd9XV/cisco_find_switch_port_from_ip_address.pdfIn PDF document text
    • https://cdn.sqhk.co/lomotutuwe/hggQXvg/drunk-_fu_wasted_masters.pdfIn PDF document text
    • https://fitulukuj.weebly.com/uploads/1/3/4/2/134265825/viwoludoribobetarus.pdfIn PDF document text
    • https://sadozilodefizon.weebly.com/uploads/1/3/4/6/134659806/japavowakomenuz-vesesarosesivu.pdfIn PDF document text
    • https://kevelowomovozi.weebly.com/uploads/1/3/4/0/134012304/438011.pdfIn PDF document text
    • http://copyrightshelpscenters.com/power_book_ghost_last_episodei5dxn.pdfIn PDF document text
    • https://e60c805d-b9e1-47fc-b045-983511e9ac1f.filesusr.com/ugd/116bb2_385773140c4942b88135aa6054f62a17.pdf?index=trueIn PDF document text
    • https://26577e91-18e8-42c3-8e85-49dcca1d6605.filesusr.com/ugd/195787_1f12e326ae574c52892fea7c0e8d5c02.pdf?index=trueIn PDF document text
    • http://felugibesixe.onlinewebshop.net/edgar_allan_poe_download_portugues.pdfIn PDF document text
    • http://wowutuzineko.myartsonline.com/an_integrated_approach_to_strategic_management.pdfIn PDF document text
    • https://5405d108-7f1e-482b-a10c-e06f62b7505d.filesusr.com/ugd/d941b1_ecce1f77815a4ebca264ff293f56bd94.pdf?index=trueIn PDF document text
    • https://11484d69-1612-41b9-9199-165df1f08223.filesusr.com/ugd/e2f197_f671bc7bd46f4a019c01fd25cd916e2d.pdf?index=trueIn PDF document text