Malicious PDF — malware analysis report

Static analysis result for SHA-256 884f50a0eeb77def…

MALICIOUS

PDF

207.7 KB Created: 2018-04-25 17:04:23 +03:00 Authoring application: wkhtmltopdf 0.12.4 (via Qt 4.8.7) First seen: 2021-11-21
MD5: c520d55bd0329aa5b4cdf602ad5ff77a SHA-1: 5c69943cacfe23fc7b8bb03f3ba54b892e1ce526 SHA-256: 884f50a0eeb77def972c60d77b5fa2926f11ec766ec6051e0ab6e97653ab1332
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains multiple heuristics indicating it is a lure for cracked software. It embeds external URIs pointing to potentially malicious websites, specifically advertising pirated software. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted, but the embedded URLs suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9696

Heuristics 3

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://renimba.info/wp1?keyword=%D0%BA%D0%B0%D0%BA+%D0%BF%D0%B8%D1%81%D0%B0%D1%82%D1%8C+%D1%81%D0%BE%D1%87%D0%B8%D0%BD%D0%B5%D0%BD%D0%B8%D0%B5+%D0%BF%D0%BE+%D1%80%D1%83%D1%81%D1%81%D0%BA%D0%BE%D0%BC%D1%83+%D1%8F%D0%B7%D1%8B%D0%BA%D1%83+%D0%B5%D0%B3%D1%8D+2017+%D0%BF%D1%80%D0%B5%D0%B7%D0%B5%D0%BD%D1%82%D0%B0%D1%86%D0%B8%D1%8F PDF link annotation
    • https://thibarpobe1983.files.wordpress.com/2018/04/zogiv-gdz-po-angliiskomu-iazyku-9-klass-kaufman-rabochaia-tetrad-1-dowupopi.pdfIn PDF document text
    • https://muebiosetua1987.files.wordpress.com/2018/04/lurakevab-reshebnik-gdz-po-angliiskomu-iazyku-5-klass-kaufman-rabochaia-tetrad-gepepuxefoxagos.pdfIn PDF document text
    • https://piespanenti1979.files.wordpress.com/2018/04/dosiduvoxetegu-dens-dens-dens-skachat-pesniu-garazet.pdfIn PDF document text
    • https://tabrapoder1972.files.wordpress.com/2018/04/tebaweguwoxali-2-gruppa-upakovki-opasnykh-gruzov-klassa-3-peram.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5910/5910370_xusistrukturaessenaangliiskomegevasan.pdfIn PDF document text
    • https://muebiosetua1987.files.wordpress.com/2018/04/vigabale-zadachnik-2500-zadach-po-matematike-4-klassy-otvety-bivegifu.pdfIn PDF document text
    • https://inpetfipen1982.files.wordpress.com/2018/04/bubepeze-film-deti-90-kh-skachat-torrent-susonovojaj.pdfIn PDF document text
    • https://thibarpobe1983.files.wordpress.com/2018/04/pizozadekokofew-kim-ege-po-matematike-2016-bazovyi-uroven-skachat-jemaperiluraxi.pdfIn PDF document text
    • https://inernutbang1982.files.wordpress.com/2018/04/pajax-gdz-7-klas-ukr-mova-o-p-glazova-2007-vekiperunam.pdfIn PDF document text
    • https://img1.liveinternet.ru/images/attach/d/0//5907/5907054_nuxishpargalkipobiologiiege2016vtablitsakhskachattuxoro.pdfIn PDF document text
    • https://niememapa1982.files.wordpress.com/2018/04/fijon-skachat-igru-crossout-na-kompiuter-cherez-torrent-davupovuzifujis.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5908/5908083_pelamuaavdeevegerusskiiiazyktuketu.pdfIn PDF document text
    • https://laulupcofor1974.files.wordpress.com/2018/04/fezojuwomiluso-reshebnik-po-chechenskomu-iazyku-6-klass-iangulbaev-makhmaev-shardar-259-buvudij.pdfIn PDF document text
    • https://inernutbang1982.files.wordpress.com/2018/04/sejavaxadobax-skachat-utilitu-dlia-udaleniia-eset-nod32-dlia-android-nozezaj.pdfIn PDF document text
    • https://prooflichamko1985.files.wordpress.com/2018/04/botamobuz-uvscreencamera-5-pro-skachat-besplatno-na-russkom-iazyke-torrent-vepilugi.pdfIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000a4bb.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA4BB 1485561 bytes
SHA-256: 1718db8b7c6a44712dc1b3acee434281abf7527ebf6ea299260c2277eb5af585