Malicious PDF — malware analysis report

Static analysis result for SHA-256 6eeaeb35f5710a77…

MALICIOUS

PDF

31.7 KB Created: 2018-04-25 22:16:52 +03:00 Authoring application: wkhtmltopdf 0.12.4 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 5c6f77bc0d1d1abc793740becaffb92b SHA-1: 4e05fe1da107eff1ec83fb1dbf01fcdc9d66effc SHA-256: 6eeaeb35f5710a777cbf654e2952f5f80d69c2754e50cfa53a1dc0263dc1cf1a
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous external links, many pointing to disposable domains, and is flagged by ClamAV as a phishing attempt. The embedded URL `http://tds.advtraff2014.ru/wp2?keyword=3g+internet+apps+download` suggests a lure to download potentially malicious applications. While no scripts were explicitly extracted, the PDF structure and link farm behavior indicate a malicious intent to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9407

Heuristics 5

  • ClamAV: Pdf.Phishing.CaptchanText06210-9874300-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.CaptchanText06210-9874300-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tds.advtraff2014.ru/wp2?keyword=3g+internet+apps+download PDF link annotation
    • https://reronessgel1985.files.wordpress.com/2018/04/telutetupat-50-cent-wallpaper-download-in-da-club-mp3-songs-tesipakip.pdfIn PDF document text
    • https://inernutbang1982.files.wordpress.com/2018/04/mujewofikame-free-to-play-no-download-horror-games-nijoregufop.pdfIn PDF document text
    • https://seowalkpuzzfren1971.files.wordpress.com/2018/04/fekax-3gp-bollywood-movies-free-download-2016-rafenululeki.pdfIn PDF document text
    • https://rlinekabet1989.files.wordpress.com/2018/04/monibiwadub-optiplex-360-lan-driver-download-wotexefabalaxo.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5916/5916748_babirumaya3dmanmodelfreedownloadkiner.pdfIn PDF document text
    • https://seowalkpuzzfren1971.files.wordpress.com/2018/04/lororo-free-download-adobe-photoshop-cs3-crack-keygen-rigasatip.pdfIn PDF document text
    • https://uxtravimme1974.files.wordpress.com/2018/04/xotetonifowuxa-2007-internet-explorer-download-xp-9-free-for-vista-fofew.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5916/5916613_xebedownloadgta1paraandroidraku.pdfIn PDF document text
    • https://velpdinazi1983.files.wordpress.com/2018/04/zamujesabozas-100-free-download-adobe-photoshop-cs6-trial-version-highly-compressed-mifemem.pdfIn PDF document text
    • https://spinindigtard1987.files.wordpress.com/2018/04/guwavaw-assassins-creed-4-black-flag-free-download-pc-full-rogaravuzusomos.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5916/5916242_xiswwebattleground2015themesongsdownloadfime.pdfIn PDF document text
    • https://img1.liveinternet.ru/images/attach/d/0//5917/5917055_poziadobephotoshopbiblefreedownloadforwindows8fullversionkowu.pdfIn PDF document text
    • https://thirsnanagtheo1974.files.wordpress.com/2018/04/noremuregufu-uc-browser-ad-download-for-samsung-galaxy-y-android-xezakikezuz.pdfIn PDF document text
    • https://crochweiflexle1978.files.wordpress.com/2018/04/zefus-autodesk-3ds-max-2012-portable-free-downloads-for-mac-lapex.pdfIn PDF document text
    • https://fienostpisal1977.files.wordpress.com/2018/04/balisamevelak-3ds-max-2009-vray-free-download-fawikuresa.pdfIn PDF document text