Malicious PDF — malware analysis report

Static analysis result for SHA-256 498b82f991089ccb…

MALICIOUS

PDF

271.6 KB Created: 2021-01-05 21:11:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: ef71f13eb7590169a79ba92fc8ff696a SHA-1: 8a5b2d7063b118964076dce5a745b2db3eb0a255 SHA-256: 498b82f991089ccbc498578c63481375dd5660c44f25e8796faced27d91af2cb
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing a malicious redirector link to 'traffine.ru'. This indicates an attempt to lure the user to a potentially harmful website. The ML classifier and ClamAV detection further support its malicious nature. No scripts were extracted, but the embedded URL is the primary indicator of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9678

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/aws?utm_term=aua+guidelines+surgical+management+of+stones In PDF document text
    • https://cdn-cms.f-static.net/uploads/4500425/normal_5fe759af5c6bd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4476578/normal_5fb320306a56a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4443819/normal_5fa6f885c50f0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366336/normal_5fb33a8452490.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4448347/normal_5fd7bf8f81897.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4408863/normal_5fcd87388f2c7.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/10c79fdc-b780-4d12-8e28-76096fb12758/il_parait_que_subjonctif_ou_indicati.pdfIn PDF document text
    • https://s3.amazonaws.com/farezelof/96598908013.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/68e356c3-8266-4431-9d58-2f275b88b9e5/download_crt_video_geometry_calibrator_dvd.pdfIn PDF document text
    • https://s3.amazonaws.com/jofunozuzof/80552722860.pdfIn PDF document text
    • https://s3.amazonaws.com/bisazabe/chicago_mayoral_election_2019_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/palikuvexake/asus_pc_performance_test.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6985a8ec-1e70-43ea-a199-2c1997e73c91/puvofaped.pdfIn PDF document text
    • https://s3.amazonaws.com/buxoparadazegu/tipos_de_afrontamiento_del_estres.pdfIn PDF document text