Malicious PDF — malware analysis report

Static analysis result for SHA-256 19217dc0629f3538…

MALICIOUS

PDF

23.2 KB Created: 2020-10-17 13:43:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 0c189a1ec3c64807731b8444a361a9f1 SHA-1: 1484736fa8b1034ad7f882fd78eb9eedb25097fd SHA-256: 19217dc0629f353874e85479c27eacfdc64fcb3e67692ad23fc31f52032d3a4f
182 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links to external websites, many of which are hosted on disposable domains, indicating a link farm designed to drive traffic to malicious redirectors. One such redirector URL is https://gettraff.ru/strik?keyword=i+saw+the+devil+torrent, which is flagged as malicious. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/strik?keyword=i+saw+the+devil+torrent In PDF document text
    • https://cdn-cms.f-static.net/uploads/4373511/normal_5f89ee81c9f36.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375504/normal_5f896684e8fe6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368770/normal_5f89f6d60e915.pdfIn PDF document text
    • https://tavumake.weebly.com/uploads/1/3/2/7/132740551/gerilulivomek.pdfIn PDF document text
    • https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/mudonij-tojoxe-xewej.pdfIn PDF document text
    • https://bilewazivabo.weebly.com/uploads/1/3/2/8/132816117/fuxusazitasorib.pdfIn PDF document text
    • https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/zuvekazabuz-topofelo-gupolekodojavo-ponabiloxe.pdfIn PDF document text
    • https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/monirafulowafix.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366044/normal_5f8715744b1a2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370989/normal_5f8a279992c89.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369496/normal_5f888244a9aaa.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368763/normal_5f88de245e3d0.pdfIn PDF document text
    • https://pepotoxuxomupav.weebly.com/uploads/1/3/1/4/131483830/99774e40eb.pdfIn PDF document text
    • https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/da0366c694e301c.pdfIn PDF document text
    • https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/388769.pdfIn PDF document text
    • https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/jovegoxo.pdfIn PDF document text
    • https://sukowaletudevux.weebly.com/uploads/1/3/0/8/130874669/8266814.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c898c0f9-3bf7-4dd3-88a1-db07372eaaf3/giwelinoborawiven.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d1603aa5-4ea5-45c9-b0c6-a0c92f0cbffb/rirojivibunagopironeka.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9e2646e8-1bcf-47e8-99bd-d636c3b7687c/60736901655.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/36d497b5-8dc7-4589-8e3c-8f857dd3b2b8/33832213134.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d97538ff-0e72-49fa-959b-a0066dc83051/bulafevulelapevalib.pdfIn PDF document text