Malicious PDF — malware analysis report

Static analysis result for SHA-256 34f296e9498de163…

MALICIOUS

PDF

24.6 KB Created: 2020-10-26 15:30:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e02578d5ad698aeffcdd8325c8f80bcb SHA-1: 3517ce59b4931887b58ba9144ccd19c2297de1dd SHA-256: 34f296e9498de163b353a9792f958048fb8d92badbe87bcf7c23d938485501af
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector infrastructure, ggtraff.ru. The ML classifier also flagged this PDF with high confidence. The embedded URL is likely intended to lead the user to a phishing page or a download for a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?keyword=isometrico+instalacion+sanitaria+aut
    • https://jonipafatanepa.weebly.com/uploads/1/3/2/7/132741476/baxugifuxozarixa.pdf
    • https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/gevoderovepiru.pdf
    • https://degujipimisa.weebly.com/uploads/1/3/1/4/131453395/benimafo.pdf
    • https://kanudepu.weebly.com/uploads/1/3/2/7/132740929/pagugiz.pdf
    • https://s3.amazonaws.com/wilugugo/analytical_geometry_notes.pdf
    • https://s3.amazonaws.com/bejokazemur/tamil_to_english_words_list.pdf
    • https://s3.amazonaws.com/robumuduluwise/dfinition_de_l_alternance_codique.pdf
    • https://uploads.strikinglycdn.com/files/5fbcad89-3d78-4722-bf5d-f2769f873761/kapejoke.pdf
    • https://uploads.strikinglycdn.com/files/64624eb7-c313-4a17-959e-f9a435be63fe/71613288971.pdf
    • https://uploads.strikinglycdn.com/files/8a3452a0-3faf-4149-bfe8-e525a2fe7949/kevoxiviv.pdf
    • https://s3.amazonaws.com/fuwawibu/tp_link_access_point_configuration.pdf
    • https://s3.amazonaws.com/farezelof/doing_justice_preet_bharara.pdf
    • https://s3.amazonaws.com/sazixipame/26694689196.pdf
    • https://cdn.shopify.com/s/files/1/0268/9223/9047/files/download_game_downhill_untuk_android.pdf
    • https://cdn.shopify.com/s/files/1/0500/9951/9659/files/upgrade_px5_android_9.pdf
    • https://cdn.shopify.com/s/files/1/0440/1378/1157/files/candidiasis_oral_caso_clinico.pdf
    • https://cdn.shopify.com/s/files/1/0499/3210/7937/files/36649049958.pdf
    • https://cdn.shopify.com/s/files/1/0505/8740/2405/files/japanese_culture_traditions.pdf