Malicious PDF — malware analysis report

Static analysis result for SHA-256 456c4a1f109e06a8…

MALICIOUS

PDF

83.0 KB Created: 2021-02-23 10:50:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-20
MD5: 4ab542f572f947310b348e510c1c04e1 SHA-1: 0be3685cd5f1635f32ca6cee2b211396422b84c6 SHA-256: 456c4a1f109e06a844737e226f33f95b1e60b6a14689fa3551e8627dc5f3ed76
212 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a mass of external links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, suggests a lure related to educational content. The presence of numerous PDF links and the ML classifier's high confidence score indicate a malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8902

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/wix?keyword=volume+of+solids+worksheet+answers+with+work In PDF document text
    • https://static.s123-cdn-static.com/uploads/4466166/normal_60049606c2406.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4370530/normal_5febae5909765.pdfIn PDF document text
    • https://cdn.sqhk.co/gupidiroka/NHvicjc/eastern_front_ww2_june_1944.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4392442/normal_5ff78cbd50891.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403539/normal_5fdf2310bcaa0.pdfIn PDF document text
    • https://pexasojurez.weebly.com/uploads/1/3/1/3/131381046/zadepoluses-temegapore-naxunevurukogav.pdfIn PDF document text
    • https://cdn.sqhk.co/gobavata/ghahghj/67141473000.pdfIn PDF document text
    • https://cdn.sqhk.co/xenumobavun/Wii1Iif/joker_hd_wallpapers_1080p_download_for_mobile.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4464724/normal_5ffc5ad782272.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4371004/normal_6027804425893.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451752/normal_60335cbf53e75.pdfIn PDF document text
    • https://s3.amazonaws.com/xupimaral/57848794611.pdfIn PDF document text
    • http://lifenasixo.epizy.com/50825332534.pdfIn PDF document text
    • http://xorikija.epizy.com/my_hero_academia_season_episode_guide.pdfIn PDF document text
    • http://bopudax.epizy.com/44625052602.pdfIn PDF document text
    • https://s3.amazonaws.com/sebunuzu/ceidg-_1_wersja_1._8._8.pdfIn PDF document text
    • https://s3.amazonaws.com/rekorewexidiwo/94483605899.pdfIn PDF document text
    • http://napipipazapuka.epizy.com/4934305537.pdfIn PDF document text