Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b15945ff06faad5…

MALICIOUS

PDF

33.6 KB Created: 2020-11-09 15:57:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f1df81e119d90bb224eee31e2ae67659 SHA-1: 93ab74576702a6dd85d96aa2fe211596f0616a88 SHA-256: 1b15945ff06faad5b00e9afb8c5dc46efb7a7f273ce078468221e8ac855d67c2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a critical heuristic firing indicating it links to known malicious redirector infrastructure. The embedded URL, https://ggtraff.ru/aws?keyword=lamento+della+ninfa+text, is identified as a malicious redirector. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same URL, reinforcing its malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9976

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/aws?keyword=lamento+della+ninfa+text
    • https://cdn-cms.f-static.net/uploads/4382192/normal_5fa90c8e5e9c7.pdf
    • https://cdn-cms.f-static.net/uploads/4383913/normal_5f9f6cdd6ddb3.pdf
    • https://cdn-cms.f-static.net/uploads/4421477/normal_5fa5b8fb40dbe.pdf
    • https://cdn-cms.f-static.net/uploads/4383170/normal_5f9e52da65881.pdf
    • https://cdn-cms.f-static.net/uploads/4369768/normal_5fa59dbca137f.pdf
    • https://cdn-cms.f-static.net/uploads/4416810/normal_5f9b0d0940bca.pdf
    • https://uploads.strikinglycdn.com/files/7ac0c2b5-2900-4ec9-87be-b990c6147c63/como_aprender_a_hablar_en_publico_ander_egg.pdf
    • https://s3.amazonaws.com/nefagolom/81604648650.pdf
    • https://uploads.strikinglycdn.com/files/d192a51a-74c3-4a35-830a-837deb0257ed/pimafafoxoga.pdf
    • https://uploads.strikinglycdn.com/files/a928e181-13f2-4be7-a438-8b72a0b11957/beditite.pdf
    • https://uploads.strikinglycdn.com/files/1ca8b847-37e1-4295-9a27-b62b9ada2466/what_modification_of_the_choroid_that_is_not_present_in_humans.pdf
    • https://s3.amazonaws.com/safago/lori_loughlin_trial_date_set.pdf
    • https://s3.amazonaws.com/henghuili-files2/anxiety_assessment_tools.pdf