Malicious PDF — malware analysis report

Static analysis result for SHA-256 e6f1bfb28d84a1c4…

MALICIOUS

PDF

58.2 KB Created: 2021-04-16 14:41:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f00fec86aa45bd6f3be286a38ec9e2e1 SHA-1: f82885b56fc7a9a5f3a581dfa5fb0bb96c3e45d6 SHA-256: e6f1bfb28d84a1c4ce377f7a5c7464233d629700d705a293fd13ead761343232
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains a large number of external links, many pointing to disposable hosting, suggesting a link farm or redirection scheme. Heuristics indicate it's a phishing or trojan PDF, and ClamAV confirms it's malicious. The embedded URLs likely serve as lures to malicious sites or to download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8425

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/strik?utm_term=on+becoming+a+person+book+pdf
    • https://cdn.sqhk.co/govuzupikiwe/ffhdRih/ramorogosajuwu.pdf
    • http://net-klientov.ru/program_management_office_mission_statement4fwyr.pdf
    • https://cdn.sqhk.co/xufojidaju/Kiggd9w/44432307363.pdf
    • https://cdn.sqhk.co/nuduniguwufo/shjJC2x/reporters_notebook_pogo.pdf
    • http://contentmedialiteracy.com/lol_worlds_pick_em_guidejeis2.pdf
    • https://cdn.sqhk.co/kuburarimoku/OMVr8hg/99117296255.pdf
    • https://a9864912-ad24-422b-99f3-2d90f7703507.filesusr.com/ugd/d6af85_16338661955c44389d9d404d49424076.pdf?index=true
    • https://69b3109a-7cce-4514-9193-d2106d9976ab.filesusr.com/ugd/3c2969_d6bb304d732a423197045761d8e8ec52.pdf?index=true
    • https://6593eeda-10fe-4128-810f-cbbc79f0a4f8.filesusr.com/ugd/c0a4bf_c41f11b25a1e4b6182f1fb8323627f51.pdf?index=true
    • https://s3.amazonaws.com/xovekolamoxe/problem_solving_worksheets_grade_3.pdf
    • https://13ea8442-998f-4f14-ba3b-7f37e53a414c.filesusr.com/ugd/008a9f_3ba36b5500f040d5b02b805750927b36.pdf?index=true
    • https://06e27459-8a58-4d01-a48e-f853eab966f6.filesusr.com/ugd/55f1a0_b909c2344afc4a70a2560dcdfe082bb0.pdf?index=true
    • https://s3.amazonaws.com/xijuxosisomuna/masterbuilt_electric_smoker_parts_list.pdf
    • https://720c7b34-a033-4bf0-83ea-6be17de98aa2.filesusr.com/ugd/03ef8e_f803a91419bc49d89fe01618df67be7c.pdf?index=true
    • https://s3.amazonaws.com/tokatefozude/assamese_song_asomi._in.pdf
    • https://4edd92ed-4e96-4c3d-a837-a16c7246ae9e.filesusr.com/ugd/7c3149_5690061b9382452f8590645e270f7346.pdf?index=true
    • https://4a31e3f8-49e3-4331-b1a9-c0bb7a6b9dbc.filesusr.com/ugd/599f1c_e394e3c0171c485789d95dc41d18df5a.pdf?index=true
    • https://00c0516a-c822-4344-a779-6f74e039753d.filesusr.com/ugd/9e41f0_cf6c93f35baa4cb0a79fd3d7685bb6a7.pdf?index=true
    • https://s3.amazonaws.com/kelukakeb/66516316385.pdf
    • https://94e55d9a-ad7c-4b6b-a54a-a00202ad3087.filesusr.com/ugd/208fd7_f040d6b6e82b4385a9e2c2d1d294fd49.pdf?index=true
    • https://s3.amazonaws.com/xozeb/desktop_anime_wallpaper.pdf
    • https://ee60c613-3dd1-430d-b711-08e3dcbf0273.filesusr.com/ugd/19ce5d_dee13e0602b9474989de82ed8be420cf.pdf?index=true
    • https://d5bea983-5bca-41ba-aae6-6b688785cc77.filesusr.com/ugd/9ec29b_40b88f0ad6bf4300a2a639137c77d984.pdf?index=true
    • https://6674166f-eb58-46b1-9d38-a528bc95e02c.filesusr.com/ugd/e38d8e_955d7143391d437aae342808e57e8ac5.pdf?index=true