Malicious PDF — malware analysis report

Static analysis result for SHA-256 2385d3d357e4afde…

MALICIOUS

PDF

61.7 KB Created: 2021-09-10 04:11:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-27
MD5: fa31e3f2f7b94bb1fb1c16d3d73cb8fb SHA-1: 2230a03023bbb027ccdfa4df31e0bccab0af8652 SHA-256: 2385d3d357e4afdeaccb2ae8835ac1cdb402a153a50e0820302cd77a537e32c4
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as a malicious PDF by ClamAV. It contains numerous embedded URLs, with one heuristic specifically flagging it as a link farm on disposable hosting. The presence of external URIs and the overall structure suggest a phishing or malware distribution attempt, likely initiated via spearphishing.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3485

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://shacklefordlawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/65242590462.pdf In PDF document text
    • https://fereshtegan.net/basefile/fereshtegannet/files/gojogi.pdfIn PDF document text
    • http://archissimo.eu/userfiles/files/rilop.pdfIn PDF document text
    • http://riviera.az/userfiles/file/930992569.pdfIn PDF document text
    • http://dae-young.kr/upload/fckeditor/file/35281459821.pdfIn PDF document text
    • http://friluftsgruppen.se/wp-content/plugins/formcraft/file-upload/server/content/files/161368cace4e3c---fuwopotarafojuwugufobam.pdfIn PDF document text
    • https://stiglic.sk/userfiles/file/nefagumimeden.pdfIn PDF document text
    • https://nazrabilisim.com/calisma2/files/uploads/68068177455.pdfIn PDF document text
    • http://marinaxaraes.com.br/ckfinder/userfiles/files/82263062044.pdfIn PDF document text
    • http://manvilastrust-org.bvirani.com/ckfinder/userfiles/files/64730760898.pdfIn PDF document text
    • http://conniecorsentino.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/73561112858.pdfIn PDF document text
    • https://livres-arts.com/ckfinder/userfiles/files/7336533773.pdfIn PDF document text
    • http://criollo-cocoa.com/userfiles/file/juduj.pdfIn PDF document text
    • https://bilbox.es/wp-content/plugins/super-forms/uploads/php/files/8c89e0b534a31d4d6195ea6e5dfaede7/28930784006.pdfIn PDF document text
    • http://benthanhsgfarm.com/images/uploads/files/35790948329.pdfIn PDF document text
    • http://maradonasalud.com.ar/ckeditor/ckfinder/userfiles/files/pagudikezoxudafikotem.pdfIn PDF document text
    • https://dalycity.com/wysiwygfiles/file/xujusawilojagov.pdfIn PDF document text
    • https://www.tamilsaga.com/ckfinder/userfiles/files/xulajusututanobabenedoz.pdfIn PDF document text
    • https://asset-books.com/userfiles/file/pitukog.pdfIn PDF document text
    • https://mtydizayn.com/userfiles/file/fejilazuwemifan.pdfIn PDF document text
    • https://vantainoidia.vn/ci/userfiles/files/9237856122.pdfIn PDF document text
    • http://geriatriccarenewjersey.com/userfiles/files/27693013447.pdfIn PDF document text
    • https://gs-hemeringen.de/ablage/userfiles/files/23602538835.pdfIn PDF document text
    • http://freeorden.com/media/file/87421421151.pdfIn PDF document text
    • https://www.artikel238.nl/emmwebbit/resources/ckfinder/userfiles/files/wiwor.pdfIn PDF document text
    • http://commissioncollectionlaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/derokapujodapipafabito.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=tv+show+downloader+apkPDF link annotation