Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c98a5826d215f6a…

MALICIOUS

PDF

33.6 KB Created: 2020-11-09 15:22:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 832caa7c5ce4bf8ac767b5c8e2b7639e SHA-1: e8bb2d311d5b17cb4b345c518660ea933eea8407 SHA-256: 2c98a5826d215f6a651ebd92fa42ec8933dc735b04307c0984f75eaf28f68212
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded links, with at least one identified as a malicious redirector. The document body, though heavily obfuscated, contains a URL that appears to be part of a link farm designed to drive traffic to malicious infrastructure. The presence of many external PDF links suggests a coordinated effort to distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/aws?keyword=what+did+the+greek+philosophers+believe+in
    • https://lurevovikofa.weebly.com/uploads/1/3/4/6/134693735/3c6986e.pdf
    • https://naxazutip.weebly.com/uploads/1/3/4/6/134610322/20d0020b.pdf
    • https://sisodiwitamusoz.weebly.com/uploads/1/3/2/6/132681746/7403683.pdf
    • https://piteselijofer.weebly.com/uploads/1/3/4/6/134608400/tebixuf.pdf
    • https://uploads.strikinglycdn.com/files/502184cc-5769-4adc-ad5b-32952ba95982/14244802088.pdf
    • https://s3.amazonaws.com/jakujakula/87105530458.pdf
    • https://uploads.strikinglycdn.com/files/82fd0716-b6b6-4de2-88a6-824d0d14fe51/46336464944.pdf
    • https://uploads.strikinglycdn.com/files/7cf42339-2048-4dac-80b5-881dca977dcb/41031436893.pdf
    • https://s3.amazonaws.com/wexukufedepim/nirvana_buddhism.pdf
    • https://s3.amazonaws.com/wexukufedepim/movaxizafuzabuzu.pdf
    • https://uploads.strikinglycdn.com/files/3a6ba2e0-ae59-43d5-912b-adf4757ecf25/nivapofivuxej.pdf
    • https://uploads.strikinglycdn.com/files/c6aa8f41-8245-4e48-8245-29d40a24427c/vintage_tupperware_rice_steamer.pdf