Malicious PDF — malware analysis report

Static analysis result for SHA-256 8855acea9689c8b7…

MALICIOUS

PDF

50.6 KB Created: 2021-04-06 08:50:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 492b320283ada460f2fb2387f03a6e51 SHA-1: 106fbf65ae0c110be9368f6d390ffb42e73f9ebe SHA-256: 8855acea9689c8b76484d61d16d80790580f478e6c047b7683e09327710faab2
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded URLs, with one prominently featuring 'arris tg862g advanced login password of the day' in its query parameters, suggesting a phishing lure. Heuristics indicate this PDF is a link farm on disposable hosting, and ML classifiers and ClamAV detect it as malicious. While no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a phishing campaign aiming to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9372

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/aws?utm_term=arris+tg862g+advanced+login+password+of+the+day PDF link annotation
    • http://zitarekatinupas.sportsontheweb.net/xuzemoribekifug.pdfIn PDF document text
    • http://juluzenaluziwo.22web.org/how_do_i_sync_my_logitech_mk700_keyboard.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370294/normal_60293d45d35d3.pdfIn PDF document text
    • http://zakosemej.mypressonline.com/voxegenofawubinuwerapuma.pdfIn PDF document text
    • http://kilubome.iblogger.org/cemal_sreya_st_kalsn.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4484999/normal_5ffed3529be98.pdfIn PDF document text
    • https://cdn.sqhk.co/bofepefurep/nJyttN8/free_whatsapp_app_for_android_phone.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455898/normal_601ecdb043e2c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4446638/normal_604f11e18f7ab.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4422137/normal_5feafd8a96296.pdfIn PDF document text
    • http://kelimap.mywebcommunity.org/wadetasinipoxewoxikikar.pdfIn PDF document text
    • https://cdn.sqhk.co/kiribikiv/Chjgeia/1248868563.pdfIn PDF document text
    • https://s3.amazonaws.com/xubifupi/autotransformer_starter_timer.pdfIn PDF document text
    • http://xawoforusur.epizy.com/mortified_guide_trailer.pdfIn PDF document text
    • http://javonipuro.epizy.com/69751610579.pdfIn PDF document text
    • http://namerunu.rf.gd/paint_3d_free_for_windows_8._1.pdfIn PDF document text
    • https://s3.amazonaws.com/ruzaganog/32491099511.pdfIn PDF document text
    • http://zimopup.myartsonline.com/kilixis.pdfIn PDF document text
    • https://s3.amazonaws.com/rorives/glandular_system.pdfIn PDF document text
    • https://s3.amazonaws.com/bulalowisu/oncourse_skip_downing.pdfIn PDF document text
    • http://peforuk.rf.gd/demifuvunoreka.pdfIn PDF document text