Malicious PDF — malware analysis report

Static analysis result for SHA-256 acf0dd08add0e223…

MALICIOUS

PDF

52.6 KB Created: 2020-12-30 21:05:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: aa13d9e24403923f249effae47335f24 SHA-1: b95f99239f4524ed114914e83fe7e6efb4be5704 SHA-256: acf0dd08add0e223e44ffa302e81e81a36d71a93a87a94819c381516c3f29496
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing a link to a known malicious redirector. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded URL is likely intended to lure users into downloading further malware or visiting a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7362

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/wb?keyword=house%20flipping%20spreadsheet%20template%20free In PDF document text
    • https://cdn.sqhk.co/kufejeni/dy1Ogil/pimugejasuvizawejurenaf.pdfIn PDF document text
    • https://cdn.sqhk.co/mepetiruzi/g4F1Sic/nededivirirukilawuzos.pdfIn PDF document text
    • https://cdn.sqhk.co/zetanitanedo/ihhegi2/final_fantasy_iv_pc_cheat_engine.pdfIn PDF document text
    • https://cdn.sqhk.co/dakubakasilu/cijjgjd/spotlight_x_room_escape_level_1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470224/normal_5fb81e09ae428.pdfIn PDF document text
    • https://cdn.sqhk.co/kitaparek/bibigjg/ap_us_history_quizlet_chapter_3.pdfIn PDF document text
    • https://cdn.sqhk.co/xojoweva/HWihjfG/caption_profile_pic_bangla.pdfIn PDF document text
    • https://cdn.sqhk.co/zetanitanedo/gYiggeD/benutose.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4481403/normal_5febb529aa1df.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374703/normal_5fb5440c3dccc.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4469359/normal_5fd71d8575915.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/99fadb7c-0326-4789-b508-a2e24036a566/nibixebavuwav.pdfIn PDF document text
    • https://s3.amazonaws.com/fogibi/reddit_best_premium_android_games.pdfIn PDF document text
    • https://s3.amazonaws.com/wozowuledij/58828126006.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9da7da07-2bc8-495e-8375-22828b2406a7/asus_laptop_battery_replacement_x551m.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38005842-6a2f-49d2-a976-79a719d93e77/december_dice_game.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa952295-28ea-423f-bc42-da6112b237d9/sisug.pdfIn PDF document text