Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b219a5f6dbeeceb…

MALICIOUS

PDF

50.6 KB Created: 2020-12-22 15:15:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 467d054b5deef40d741efd5b17ee16d7 SHA-1: 4a06ed2588d9440e2ac5ef447d631ea67734324e SHA-256: 2b219a5f6dbeecebfefa4b856e4388f18c402d5a421ea925cf39992e19ed6e22
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8633

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/aws?utm_term=wechat+video+call+free++for+pc PDF link annotation
    • https://dajilifu.weebly.com/uploads/1/3/4/8/134891154/kufizabed-geranulat.pdfIn PDF document text
    • https://wubinuju.weebly.com/uploads/1/3/4/6/134642725/3320685.pdfIn PDF document text
    • https://nirilixurem.weebly.com/uploads/1/3/4/4/134474770/fiwekuwulodiwo_jogefarazu_lijafalulogax_kanabew.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f8d0657-765c-4760-aaa2-f88ff6a512c3/adobe_photoshop_touch_apk_download_latest_version.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9e2a9c72-795c-40d0-8c42-58d73761af77/15047557401.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fdc9c274a508b35dd5dc321/t/5fdcdcdd54d4e200dce7d363/1608309983533/full_form_of_cgs_unit_in_physics.pdfIn PDF document text
    • https://s3.amazonaws.com/jonora/biomes_of_the_world_worksheet_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d22e9ae1-1718-4077-9df9-6dcd22933e8c/sudixoraperilu.pdfIn PDF document text
    • https://s3.amazonaws.com/muvarelo/38132197944.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe34d23c6ccf69f3298dbe/1606300884372/dilexixekabilajutekoruje.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a67a2f5-570c-4410-8531-9a2045bc1556/microsoft_office_professinal_2003.pdfIn PDF document text