Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b2a35d1a1bc7ebc…

MALICIOUS

PDF

32.6 KB Created: 2020-11-09 15:57:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b95fcf582e6cc36f3ca9908c811eabb9 SHA-1: 1da7d1a9188de9f470b84c63febbd3e8c8d4fd1e SHA-256: 4b2a35d1a1bc7ebccb33eafcbba78e24e00a0af49b215de1870fb270dcd7c364
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ggtraff.ru/aws?keyword=lamento+della+ninfa+text'. The ML classifier also strongly flagged this PDF as malicious. While no scripts were extracted, the embedded URL is the primary indicator of malicious intent, likely serving as a lure to a phishing site or a download host for further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9977

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/aws?keyword=lamento+della+ninfa+text
    • https://cdn-cms.f-static.net/uploads/4382192/normal_5fa90c8e5e9c7.pdf
    • https://cdn-cms.f-static.net/uploads/4383913/normal_5f9f6cdd6ddb3.pdf
    • https://cdn-cms.f-static.net/uploads/4421477/normal_5fa5b8fb40dbe.pdf
    • https://cdn-cms.f-static.net/uploads/4383170/normal_5f9e52da65881.pdf
    • https://cdn-cms.f-static.net/uploads/4369768/normal_5fa59dbca137f.pdf
    • https://cdn-cms.f-static.net/uploads/4416810/normal_5f9b0d0940bca.pdf
    • https://uploads.strikinglycdn.com/files/7ac0c2b5-2900-4ec9-87be-b990c6147c63/como_aprender_a_hablar_en_publico_ander_egg.pdf
    • https://s3.amazonaws.com/nefagolom/81604648650.pdf
    • https://uploads.strikinglycdn.com/files/d192a51a-74c3-4a35-830a-837deb0257ed/pimafafoxoga.pdf
    • https://uploads.strikinglycdn.com/files/a928e181-13f2-4be7-a438-8b72a0b11957/beditite.pdf
    • https://uploads.strikinglycdn.com/files/1ca8b847-37e1-4295-9a27-b62b9ada2466/what_modification_of_the_choroid_that_is_not_present_in_humans.pdf
    • https://s3.amazonaws.com/safago/lori_loughlin_trial_date_set.pdf
    • https://s3.amazonaws.com/henghuili-files2/anxiety_assessment_tools.pdf