Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fe29da4106557cc…

MALICIOUS

PDF

51.6 KB Created: 2021-06-11 02:49:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: fabd69e597ec1c4712c657081d4a008d SHA-1: 701f9e3beddfa5cbf0038888e831efdf9ffc5dda SHA-256: 5fe29da4106557cc4350cd550e8491b47f8a9f6a0557ec0b9d23b49982463f08
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9220

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://philabc.ru/pbw?utm_term=captain+america+first+avenger+full+movie PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4456116/normal_5fdc1181d0bb7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4390642/normal_60c0b9bf2478a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4464068/normal_6007466e1eb13.pdfIn PDF document text
    • https://sifelinapekaw.weebly.com/uploads/1/3/1/6/131637019/145448.pdfIn PDF document text
    • https://foxanebipukete.weebly.com/uploads/1/3/4/3/134309218/8489812.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4446388/normal_5ff7e6b76f06e.pdfIn PDF document text
    • https://nomomiwadij.weebly.com/uploads/1/3/3/9/133997716/1165267.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4388157/normal_5febf091e8765.pdfIn PDF document text
    • https://fuxaxogajumuw.weebly.com/uploads/1/3/1/4/131406658/d626fad77b.pdfIn PDF document text
    • https://lijupumo.weebly.com/uploads/1/3/4/4/134496400/vapubome.pdfIn PDF document text
    • https://guzoxufogoxuwo.weebly.com/uploads/1/3/4/0/134097696/4010494.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4445128/normal_6035f745a71a8.pdfIn PDF document text
    • https://dasubafetimediz.weebly.com/uploads/1/3/4/6/134673415/butipafep-nokatifupufiri-buzixul.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4471488/normal_60b6182cef494.pdfIn PDF document text
    • https://mawobomogagot.weebly.com/uploads/1/3/4/1/134109187/wuvura_xurusatabiru_falidugevamugak.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369164/normal_604c98b4c7f7a.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/46265090-f135-4a2a-a30b-84a627eb3b88/amapiano_sample_packs_sendspace.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/26080eb8-fcb5-4098-80c1-6ded4225268e/gosetivupisakej.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b5673406-5fe7-413d-ab55-60a5d335114b/vuvelirisagidezubigemase.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/66b6af85-a604-4d0f-a4fd-a806cae75c0b/28155419447.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/50e81b21-43b4-4c84-beae-26713a506973/breakfast_club_full_script.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f988c0ce-41b2-4124-b7cc-634c9bed0eb0/nintendo_switch_games_on_sale_walmart.pdfIn PDF document text