Malicious PDF — malware analysis report

Static analysis result for SHA-256 10edaa3b83ea5581…

MALICIOUS

PDF

47.5 KB Created: 2020-10-11 16:32:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 546f5cdb311667e789cc3318c9853f2e SHA-1: c76d6042124ceaea08b7c73d2aba7d6bbba0009d SHA-256: 10edaa3b83ea55812934fe56b7a05779c709f30512f57be6dd18bbf4ba750d18
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains a large number of links to external documents, a common tactic for link farms and SEO manipulation. One of these links points to a known malicious redirector, indicating a malicious intent to lead the user to harmful content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9955

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/strik?keyword=gloeocapsa+prokaryotic+or+eukaryotic
    • http://files.ciarchitect.com/uploads/1/3/0/7/130739811/sulowisozidegeremo.pdf
    • http://xajebam.corenewal.org/uploads/1/3/1/0/131070571/xonex.pdf
    • http://files.moncarnetdelecture.com/uploads/1/3/0/8/130874430/9e5d7d9352619.pdf
    • http://files.rockphenoms.com/uploads/1/3/2/8/132815785/6dc05f.pdf
    • https://cdn.shopify.com/s/files/1/0482/5366/5442/files/bizelavubakula.pdf
    • https://cdn.shopify.com/s/files/1/0437/8260/2904/files/1045041418.pdf
    • https://cdn.shopify.com/s/files/1/0266/8327/7491/files/dhampir_5e_midgard.pdf
    • https://cdn.shopify.com/s/files/1/0440/7623/6950/files/toshiba_satellite_s70-bbt2n23_laptop_driver.pdf
    • https://cdn.shopify.com/s/files/1/0479/2906/5639/files/josenawazupowusuxes.pdf
    • https://cdn.shopify.com/s/files/1/0484/0377/5640/files/rick_and_morty_vs_dungeons_and_dragons_download.pdf
    • https://cdn.shopify.com/s/files/1/0438/2018/7805/files/gowe