Malicious PDF — malware analysis report

Static analysis result for SHA-256 8dc6c05bc9392ec6…

MALICIOUS

PDF

47.2 KB Created: 2020-12-19 22:09:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 2f482a2b962a0f55aa0143ba5b669172 SHA-1: 288cf10be8ee497f9fecd68dbbec7e1273e79c7a SHA-256: 8dc6c05bc9392ec6ccd3dc40114980eee9b98d24b46abc89e527b53dc73e1a5f
212 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded links, with one identified as a known malicious redirector. The ML classifier and ClamAV detection further support its malicious nature. The presence of a link to 'traffmen.ru' suggests an attempt to lure the user to a malicious site, likely for phishing or to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7170

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffmen.ru/strik?utm_term=knapford+station+trackmaster In PDF document text
    • https://cdn-cms.f-static.net/uploads/4368224/normal_5fa75f541a236.pdfIn PDF document text
    • https://retariluwefise.weebly.com/uploads/1/3/4/8/134858211/mipapogizet.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365624/normal_5f87228326f1f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379387/normal_5f91b12821b06.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419836/normal_5fb939873a9b1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4402711/normal_5fc8ea81b265f.pdfIn PDF document text
    • https://fapusazi.weebly.com/uploads/1/3/4/8/134849501/b1bc94b65b28d95.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389106/normal_5fafadcc2c18c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4480161/normal_5fa7307823163.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe2f946457125654049aaf/1606299542462/symbolism_in_literature_practice_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/nawuvud/39233291123.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc14d4c5bcb0228a2853727/t/5fc8f5ce56f72563b2d07b0d/1607005647550/best_online_shopping_sites_for_electronics_in_uk.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/128985bb-bcea-4d79-9c0d-d44539df5284/form_space_and_order_4th_edition.pdfIn PDF document text