Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff403ff2624685a9…

MALICIOUS

PDF

64.0 KB Created: 2021-03-10 23:04:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4a1a3ccd6602f4529e4a2a2ee7d0c499 SHA-1: 8487e9f4c1c960d89867fef7a3ccffdc72ef3653 SHA-256: ff403ff2624685a9a12e29e384dbb860ce390b42ccb30e5e54df46e2496b9f6f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous external links, many of which are part of a link farm designed to inflate search engine rankings. The primary URL, 'https://pelibifir.ru/award?keyword=aiou+solved+assignment+2020+pdf', suggests a lure related to academic assignments. The presence of ClamAV detection and ML classification indicates malicious intent, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8189

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/award?keyword=aiou+solved+assignment+2020+pdf
    • https://static.s123-cdn-static.com/uploads/4381320/normal_5fef6bc2c5620.pdf
    • https://cdn.sqhk.co/tedubifo/ivhgidy/selesagoxurawiwojozan.pdf
    • https://static.s123-cdn-static.com/uploads/4386842/normal_6007e491c0428.pdf
    • http://trening-ekaterinodar.ru/64955989467p36vy.pdf
    • https://cdn.sqhk.co/dutaxato/cughieR/57180051792.pdf
    • http://werenntaq.online/menschen_a1._1_answerstw35j.pdf
    • https://cdn.sqhk.co/xawenano/fihbLcd/lesapetodudekes.pdf
    • https://static.s123-cdn-static.com/uploads/4494668/normal_5ffce48748329.pdf
    • https://cdn.sqhk.co/jidevumedure/nTiijhq/pofabofedakeripirupefiko.pdf
    • https://static.s123-cdn-static.com/uploads/4367297/normal_6003108f55980.pdf
    • https://cdn.sqhk.co/bidekidarub/RiiRqsA/12649938467.pdf
    • https://static.s123-cdn-static.com/uploads/4401697/normal_5ff52dad03756.pdf
    • https://uploads.strikinglycdn.com/files/b7e592a0-1eb6-443e-a9e5-ab96be90b8d7/mass_effect_2_crack_freezing.pdf
    • https://f07eb630-23ff-4298-a1df-d7940f1ba2dc.filesusr.com/ugd/097a5b_c61818b1017e48adb74edd2641f99511.pdf?index=true
    • https://uploads.strikinglycdn.com/files/0633fab8-c993-4a25-b94a-e838ac7de7e5/xidizojajefisumon.pdf
    • https://uploads.strikinglycdn.com/files/b94f3a66-0fa7-4a88-80df-b4b565980494/what_is_distributive_justice_in_healthcare.pdf
    • https://caa91486-5fcc-43b7-8b2b-5b817ae85bbe.filesusr.com/ugd/26bbcf_efd61cb245d747c385ff5230428ed166.pdf?index=true
    • https://uploads.strikinglycdn.com/files/268765bd-d28b-4013-b9de-a0b12e3388fb/mivumix.pdf
    • https://uploads.strikinglycdn.com/files/69f00605-03da-47d8-963a-8a7a0975e854/oscar_wao_masculinity_quotes.pdf
    • https://uploads.strikinglycdn.com/files/216135bc-cd13-4daa-8494-2c58a0000dc1/fun_soccer_fitness_drills.pdf
    • https://uploads.strikinglycdn.com/files/2b2a7cc7-bec8-4a72-b44e-f58b9b3b0bb3/how_to_replace_fisher_and_paykel_dryer_door.pdf
    • https://443275ec-395d-4f86-84c9-2ed7a250e117.filesusr.com/ugd/7d471d_b7b7554620a3439a8976a92319cb8285.pdf?index=true
    • https://4e4301d6-cc9a-4939-960a-6b497c1efea6.filesusr.com/ugd/d78803_449155f0213f4621bdfbbc95eee4c951.pdf?index=true
    • https://uploads.strikinglycdn.com/files/41ca6bd7-e211-4351-850d-5dfecaddeee0/60973537374.pdf
    • https://5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com/ugd/460efe_acfcd0054fc34eb7a31cfd99033ab546.pdf?index=true
    • https://uploads.strikinglycdn.com/files/602e9bdc-8892-49cd-9402-76488ba2772a/what_to_write_in_a_valentines_card_for_your_sister.pdf