Malicious PDF — malware analysis report

Static analysis result for SHA-256 afc35e05233ee1d9…

MALICIOUS

PDF

53.1 KB Created: 2021-03-10 17:54:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bf224889f2fba923e9fade1a518a4186 SHA-1: 48c7c4d6780e4f140e41713cec7530cae2983b53 SHA-256: afc35e05233ee1d98a630f522304d2a705915c4f4ef26225854c8aa64590143e
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as an image-only lure, typical of phishing or malware distribution campaigns. It contains a high number of external links, including a link to 'baarspo.ru', suggesting a coordinated effort to distribute malicious content or redirect users to phishing sites. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6839

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 53 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/award?keyword=nike+advertising+strategy+pdf
    • https://static.s123-cdn-static.com/uploads/4368477/normal_5fcdcfd8f403f.pdf
    • https://cdn.sqhk.co/zofonabiz/gethfPZ/mini_world_block_art_mod_apk_happymod.pdf
    • https://static.s123-cdn-static.com/uploads/4478438/normal_6003f9fb4ed68.pdf
    • https://cdn.sqhk.co/mozedizupi/jjhgghd/bemuxorepage.pdf
    • https://cdn.sqhk.co/boxewemutox/gcVhijf/zusakixotafobege.pdf
    • https://cdn.sqhk.co/janimivaxo/dhhgjif/ruranalimad.pdf
    • https://cdn.sqhk.co/wadalibituge/izhbpje/dularuxasafugiwi.pdf
    • https://cdn.sqhk.co/ruwonumatag/herjija/noxujosurexezamojinibedes.pdf
    • https://cdn.sqhk.co/rolizemixij/hHifdgi/race_io_mod_apk_330.pdf
    • https://cdn-cms.f-static.net/uploads/4365536/normal_600bf414e312b.pdf
    • https://cdn.sqhk.co/nujusowidom/Gmiagg0/zoxabukibivu.pdf
    • https://cdn-cms.f-static.net/uploads/4491148/normal_6045c4a7c2779.pdf
    • https://cdn-cms.f-static.net/uploads/4367643/normal_5fd1b2a91c68a.pdf
    • https://cdn-cms.f-static.net/uploads/4460228/normal_601ab7071f349.pdf
    • https://cdn-cms.f-static.net/uploads/4458623/normal_6039b45e2a6d7.pdf
    • https://6d5fec37-5936-4ae8-8938-03a86e982f09.filesusr.com/ugd/d4da64_b73a8a9b815a4e749be8c1b41bdc4549.pdf?index=true
    • https://uploads.strikinglycdn.com/files/bb151f14-f586-438f-8418-e67b317df972/types_of_poems_for_elementary_students.pdf
    • https://uploads.strikinglycdn.com/files/89aeae1a-850b-4f85-b3c8-27c86f3f6a32/ravanudularariwoje.pdf
    • https://0f4267a5-27df-427f-b7ff-de3c6d4a4cd0.filesusr.com/ugd/9e4921_b00ebf0db9a4485ca0ed8f9473e1ecf5.pdf?index=true
    • https://01477de9-116b-42a6-a62c-54244336611e.filesusr.com/ugd/dea9e9_c7c4ddb6d86c42e1b20c4eebd1d23c01.pdf?index=true
    • https://uploads.strikinglycdn.com/files/3075db23-82d7-47de-b6b6-b48e4fa78a64/metitarapikibivukaz.pdf
    • https://ebed6276-6372-4ddf-adad-9a0fa504b99f.filesusr.com/ugd/805d2a_f99c6fa7478846d4bd27f7c417420c4d.pdf?index=true
    • https://e114ad41-1367-46fe-a5fd-427bf640f69d.filesusr.com/ugd/a63c55_fc4308844cc043dcad522493200362c1.pdf?index=true
    • https://uploads.strikinglycdn.com/files/4a229474-2c74-4c4f-826e-1b49224a7c40/kapinasavolufoke.pdf
    • https://uploads.strikinglycdn.com/files/a86c710a-3689-46f8-8293-8a7753a04b93/what_to_do_to_get_real_estate_license.pdf