Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ffcd3bbec9a1d81…

MALICIOUS

PDF

16.6 KB Created: 2020-10-29 22:56:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7905b08965052a77c4b155736e8bcc50 SHA-1: 6763e08fbc190698aa22c9f7d678b4fb50e9788b SHA-256: 9ffcd3bbec9a1d813573b2191ccd1834cf716d57094d651321ee278593e46f24
112 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as an image-only lure, typical of phishing campaigns. It contains a link to a known malicious redirector infrastructure, which likely serves as the initial step in delivering a payload or leading the user to a phishing site. The document body, though heavily obfuscated, contains the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 16 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?keyword=allen+county+new+warrants
    • https://lebidupevi.weebly.com/uploads/1/3/4/3/134319251/kofesonow.pdf
    • https://gagumosesixibo.weebly.com/uploads/1/3/4/0/134018544/mugufepasa.pdf
    • https://kulinamolusamu.weebly.com/uploads/1/3/4/2/134234583/2716238.pdf
    • https://s3.amazonaws.com/kagedatabujo/behaviour_management.pdf
    • https://s3.amazonaws.com/kavitokolezub/fezat.pdf
    • https://s3.amazonaws.com/leguvefu/fofatitufategofodod.pdf
    • https://cdn.shopify.com/s/files/1/0504/1006/2012/files/donde_estas_corazon_lyrics.pdf
    • https://s3.amazonaws.com/gupuso/ganorekugevedusobubaxi.pdf
    • https://cdn.shopify.com/s/files/1/0501/2406/2908/files/luduvasipurife.pdf
    • https://s3.amazonaws.com/memul/camera_lenses_types.pdf
    • https://s3.amazonaws.com/xunilukegez/advantages_and_disadvantages_of_4g_technology.pdf
    • https://cdn.shopify.com/s/files/1/0484/8091/1515/files/99511474565.pdf
    • https://cdn.shopify.com/s/files/1/0496/5059/8044/files/destiny_2_weapon_perks_guide.pdf
    • https://cdn.shopify.com/s/files/1/0501/9713/5541/files/evolutionary_ecology_and_human_behavior.pdf
    • https://s3.amazonaws.com/muwemivumazulax/klasifikasi_acetobacter_xylinum.pdf