Malicious PDF — malware analysis report

Static analysis result for SHA-256 205914e6ba5994fc…

MALICIOUS

PDF

33.6 KB Created: 2020-10-26 15:26:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 502efca3a07a43956168cdbba0a89338 SHA-1: 7858cd6554a4527bf8b5ae084df53ed67fec4477 SHA-256: 205914e6ba5994fc48f309c159b03d453b3c624ca04f6968b90ec60085ce7261
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a high number of embedded links, many pointing to a redirector infrastructure, indicating a link farm or phishing attempt. The document body, though heavily obfuscated, contains a URL that matches the malicious redirector. The presence of embedded URLs and the ML classifier's high confidence score suggest malicious intent, likely to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?keyword=tarjeton+anticorrupcion+colombia+2018+pdf
    • https://uploads.strikinglycdn.com/files/562e819b-5c94-4c7a-9b77-9b6c59eac8ce/43959381345.pdf
    • https://uploads.strikinglycdn.com/files/da156a66-4e51-4ea8-b019-b0ab58d7cdec/57208052069.pdf
    • https://uploads.strikinglycdn.com/files/99942479-b033-40c6-810f-a7fe4e65faa4/73699726143.pdf
    • https://cdn.shopify.com/s/files/1/0266/7728/0952/files/the_skin_of_sorrow_film.pdf
    • https://cdn.shopify.com/s/files/1/0437/2011/4331/files/native_ui_gta_5_latest_version.pdf
    • https://cdn.shopify.com/s/files/1/0437/6035/3429/files/jefamuxuxeberejubeti.pdf
    • https://s3.amazonaws.com/punurum/astrophysics_for_the_person_in_a_hurry.pdf
    • https://s3.amazonaws.com/viboxikuz/chapter_3_maths_class_10.pdf
    • https://s3.amazonaws.com/gupuso/64754003706.pdf
    • https://s3.amazonaws.com/henghuili-files2/10891912430.pdf
    • https://s3.amazonaws.com/jenagubadopi/exercice_atomistique.pdf
    • https://s3.amazonaws.com/dixaleko/padubadoxoja.pdf
    • https://s3.amazonaws.com/jezaxojipevu/25295562410.pdf
    • https://s3.amazonaws.com/sabegokek/pengertian_akuntansi_keuangan.pdf
    • https://s3.amazonaws.com/wupixufekijax/mastering_accounting_skills.pdf
    • https://uploads.strikinglycdn.com/files/50ea9e9d-a331-4c84-8afb-cb3d88b7931b/kifagegi.pdf
    • https://uploads.strikinglycdn.com/files/89507865-9c7c-4886-b7cb-d47dbaaaa7fb/red_queen_free_download.pdf
    • https://uploads.strikinglycdn.com/files/cc1191df-96c4-4cdd-8295-eef0f5ad40d4/58637233035.pdf
    • https://s3.amazonaws.com/juduk/gufajuxujiripajusu.pdf
    • https://s3.amazonaws.com/zesotat/lozukodivafijolafepo.pdf
    • https://s3.amazonaws.com/gupuso/multivariate_data_analysis_using_spss.pdf