Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a3376b60e8c0da3…

MALICIOUS

PDF

16.0 KB Created: 2020-11-03 03:22:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eb9a35566db0dc4c0dbbbce90ebf4324 SHA-1: 3eea0030149626536c18af6f87321975ef57a1e7 SHA-256: 1a3376b60e8c0da39915f6df408f5298f85206e635c3c3335e5beeb9fe7dfd20
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, which is likely intended to lead the user to a phishing or malware distribution site. The document body, though heavily obfuscated, contains the malicious URL and appears to be a lure related to an academic topic. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9972

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/123?keyword=ap+biology+dna+replication+worksheet
    • https://cdn.shopify.com/s/files/1/0431/6617/1287/files/nba2k13_mobile_apk_download.pdf
    • https://s3.amazonaws.com/fuwawibu/bhagavad_gita_chapter_17_english.pdf
    • https://cdn.shopify.com/s/files/1/0504/5770/6689/files/history_of_occultism.pdf
    • https://cdn.shopify.com/s/files/1/0437/1218/4474/files/zebezij.pdf
    • https://s3.amazonaws.com/wavunot/vibajiwifuko.pdf
    • https://cdn.shopify.com/s/files/1/0499/3328/7586/files/fekaj.pdf
    • https://uploads.strikinglycdn.com/files/77c05b41-3ed0-405f-a6d0-7ef8b3d88b73/7814949993.pdf
    • https://cdn.shopify.com/s/files/1/0268/7415/1083/files/mitidawitojuwogaletakose.pdf
    • https://uploads.strikinglycdn.com/files/6bfb2bc0-0120-4d6b-825d-6b0de044c4a0/44921858827.pdf
    • https://cdn.shopify.com/s/files/1/0500/0328/0027/files/sql_server_database_mirroring_manual_failover.pdf