Malicious PDF — malware analysis report

Static analysis result for SHA-256 a09d76c40ef38cca…

MALICIOUS

PDF

83.0 KB Created: 2020-11-19 22:29:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: de858f5cf578445b9fd0c7f49d0e7d6b SHA-1: fa354b39d27b5bb45c89c3d2cb1353323a59f000 SHA-256: a09d76c40ef38ccacd2eb5ecc45159390271f329f102f4288d663e9a15ae8501
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ggtraff.ru/strik?utm_term=dominic+d%252527agostino+fasting'. This indicates the document's primary purpose is to lure the user to this malicious site. The ML classifier also flagged the PDF as malicious, supporting this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7490

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?utm_term=dominic+d%252527agostino+fasting
    • https://cdn-cms.f-static.net/uploads/4366047/normal_5fae7690af37d.pdf
    • https://s3.amazonaws.com/sojuravewi/fuerzas_intermoleculares_dipolo_dipolo.pdf
    • https://s3.amazonaws.com/sezewu/bloons_td_5_hack_download_for_pc.pdf