Malicious PDF — malware analysis report

Static analysis result for SHA-256 782d9283970c64bd…

MALICIOUS

PDF

56.3 KB Created: 2020-12-14 03:25:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 969548140d94479d5f73d4a17102a3eb SHA-1: 7dba017b0ed53b03d81e16ac4936a710a5213128 SHA-256: 782d9283970c64bd5c62db29d4b1f8a43cc24901cdcc77a58825c2285070df1c
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document is identified as malicious by ClamAV and ML classifiers, exhibiting characteristics of a phishing lure. It contains a single image and minimal text, typical of a screenshot designed to conceal a clickable link. The document embeds multiple external URIs, including one that appears to be a tracking or redirect URL, suggesting an attempt to lead the user to a malicious site for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8985

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 56 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/strik?utm_term=walking+dead+no+man%2527s+land+apk+offline
    • https://cdn-cms.f-static.net/uploads/4367938/normal_5f924e8c3e3f9.pdf
    • https://rogefiraf.weebly.com/uploads/1/3/4/5/134581109/2061d2f7b48940.pdf
    • https://cdn-cms.f-static.net/uploads/4390330/normal_5f9a775de4122.pdf
    • https://tadomowiwelam.weebly.com/uploads/1/3/4/7/134744739/4476451.pdf
    • https://cdn-cms.f-static.net/uploads/4367914/normal_5f901261f2e20.pdf
    • https://cdn-cms.f-static.net/uploads/4369323/normal_5fada0ab140e3.pdf
    • https://makonajarozov.weebly.com/uploads/1/3/4/3/134341931/e9aa2d8ee7829.pdf
    • https://tibulewozimok.weebly.com/uploads/1/3/4/0/134017320/2777475.pdf
    • https://cdn-cms.f-static.net/uploads/4463006/normal_5fa9fd65e78e9.pdf
    • https://static1.squarespace.com/static/5fc29729405d5340f33472fa/t/5fc744c1bfb90028be4e783a/1606894785829/dancing_ballet_health_related_components.pdf
    • https://s3.amazonaws.com/luborinizu/citizenship_application_study_guide.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbcf86a9d104e5f152d6f1c/1606219883052/goxeriwogunejunabekuxop.pdf
    • https://static1.squarespace.com/static/5fc4d9052e537a05ef22535d/t/5fc6a9e8bc819f1cf4c3d325/1606855145240/mesa_az_rock_climbing.pdf
    • https://s3.amazonaws.com/fulazelof/41519641268.pdf