Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f3370f08084f843…

MALICIOUS

PDF

25.8 KB Created: 2020-09-07 11:17:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 62c2d72486167b722e6aea5dfe309da6 SHA-1: c1412be5ae6e671fe329950ff73a685205428efe SHA-256: 2f3370f08084f843513b7a0b0f6c2b782e54ffc17c57971bea5a077eed495a07
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, which is designed to trick users into downloading potentially harmful software. The embedded URL is part of a lure for a software crack, indicating a phishing or social engineering attempt. No scripts were extracted, but the presence of a malicious redirector is a strong indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9963

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=blender+animation+software+crack
    • https://cdn.shopify.com/s/files/1/0461/1617/6036/files/aerobic_performance_definition.pdf
    • https://cdn.shopify.com/s/files/1/0434/0717/9941/files/76893758958.pdf
    • https://cdn.shopify.com/s/files/1/0430/6403/3429/files/64352954853.pdf
    • https://cdn.shopify.com/s/files/1/0431/9726/8128/files/flower_wallpaper_for_android_mobile.pdf
    • https://cdn.shopify.com/s/files/1/0432/5592/2856/files/fuvefojagewofamomafotu.pdf
    • https://static.usrfiles.com/ugd/49be48_a91a722c7df740808d9b9ec3f0e96c73.pdf
    • https://static.usrfiles.com/ugd/f63f29_ee3b63b412e547e693654ff71cb22a1a.pdf
    • https://static.usrfiles.com/ugd/5926b4_c970e29927404963a2eb28f62bf0e33d.pdf
    • https://static.usrfiles.com/ugd/9b33c5_17657e4c5a154cc19e2b7a99d39ec77b.pdf