Malicious PDF — malware analysis report

Static analysis result for SHA-256 5587fc03d23388d2…

MALICIOUS

PDF

59.6 KB Created: 2021-04-11 05:52:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 0b985ca1edaf4a5dfb51e6d154490c55 SHA-1: 64f5a5de3df039f0a8ee8808400bdc7d5692b47e SHA-256: 5587fc03d23388d201f293a623d396a0adbca182a1d084eabf71bc97f262ce07
242 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document functions as a link farm, embedding numerous URLs that lead to external resources. Heuristics indicate these links are part of a malicious redirector infrastructure and a disposable link farm on potentially untrusted hosting. The embedded URLs, such as 'https://yafferge.ru/strik?utm_term=why+is+my+heating+blanket+blinking', are designed to direct users to malicious sites, likely for phishing or malware distribution. The ClamAV detection further supports its malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5493

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=why+is+my+heating+blanket+blinking In PDF document text
    • http://marinarus.space/rivorubebizxufjf.pdfIn PDF document text
    • https://lolutisoxat.weebly.com/uploads/1/3/4/3/134315909/8226277.pdfIn PDF document text
    • http://werenntaq.online/faxozudupozepefabud54re1.pdfIn PDF document text
    • https://zunudomulu.weebly.com/uploads/1/3/4/6/134604261/nulevodokisupom-tuziwaxojupet-jejesijedo.pdfIn PDF document text
    • https://wajotirege.weebly.com/uploads/1/3/5/3/135306859/jixavulejinaburo.pdfIn PDF document text
    • http://merovew.xyz/29635284574gujmt.pdfIn PDF document text
    • https://fotobuwab.weebly.com/uploads/1/3/4/3/134368258/zerulazasirex_tijax_xaxuzudizomikim_wijuregoxikud.pdfIn PDF document text
    • http://nextauto02.ru/pejezixotejunob74fbx.pdfIn PDF document text
    • http://fruit-ital.space/its_kind_of_a_funny_story_netflix_castwprm6.pdfIn PDF document text
    • https://visegonikagade.weebly.com/uploads/1/3/4/6/134626066/fewulamexirerid.pdfIn PDF document text
    • http://gulibej.22web.org/casio_fx-_95es_plus_manual.pdfIn PDF document text
    • https://zunitilamurako.weebly.com/uploads/1/3/4/5/134529552/ecd6112.pdfIn PDF document text
    • http://reduslimer.website/455654118716hbru.pdfIn PDF document text
    • https://rukuzidin.weebly.com/uploads/1/3/4/5/134517246/8919253.pdfIn PDF document text
    • http://sexesex.site/why_does_my_dog_put_toys_in_my_face820qu.pdfIn PDF document text
    • http://mujumuvibofa.iblogger.org/95811140285.pdfIn PDF document text
    • https://nuvuxupu.weebly.com/uploads/1/3/4/5/134507381/1830850.pdfIn PDF document text
    • https://mitesevutij.weebly.com/uploads/1/3/4/7/134717039/d3f62.pdfIn PDF document text
    • https://xofivexaroza.weebly.com/uploads/1/3/4/3/134321457/tutavatojeta_losufofoba_pezumimamakiba.pdfIn PDF document text
    • http://heliusdesign.ru/98791992677qv7la.pdfIn PDF document text
    • http://sizatopus.rf.gd/nezavanusebiwumefofokir.pdfIn PDF document text
    • http://bimumebuzof.epizy.com/smokey_mountain_smoker_assembly.pdfIn PDF document text
    • http://tativukowodugox.epizy.com/zufegademiga.pdfIn PDF document text