Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9d478f99e1b361d…

MALICIOUS

PDF

51.0 KB Created: 2020-12-06 01:15:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: 31ce75eb69e6ea287c042545d6fcf714 SHA-1: 396f21e87771bf42bc44fd74d184f960abb0f07b SHA-256: b9d478f99e1b361d9cd95b2f29c16492dba8499bb4bf5a26ce1e4d4469cebf92
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://traffine.ru/strik?utm_term=ff14+patron+deity+matter'. This indicates the document's primary purpose is to lure the user to a potentially harmful external site. The ML classifier and ClamAV also flagged this file as malicious, supporting the assessment of a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7181

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/strik?utm_term=ff14+patron+deity+matter In PDF document text
    • https://datevapo.weebly.com/uploads/1/3/4/3/134338939/6138718.pdfIn PDF document text
    • https://liletalezawo.weebly.com/uploads/1/3/4/5/134591830/515f2.pdfIn PDF document text
    • https://buximinolid.weebly.com/uploads/1/3/1/3/131381316/7579397.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385214/normal_5f918a4cc8464.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc4f5382bbd740658208855/t/5fc6b92d788a962b7c160ce9/1606859053469/snake_game_online_with_friends.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0e110403f5353fd95a22f/t/5fc404309b1ed035385a3370/1606681648973/ffxiv_nidhogg_ex.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd4506de5dd04e4f76bc98/1606239494069/hotel_montana_haiti_before_earthquake.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0e727ea4a794d5645064f/t/5fc142793570fb44d130d900/1606500985433/99323224762.pdfIn PDF document text
    • https://s3.amazonaws.com/tanapilamaxi/47822166161.pdfIn PDF document text
    • https://s3.amazonaws.com/dezajok/ratedazasetujoreravanaxo.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc34a14bda9c57a97cd8cb5/t/5fc52f3b9b1ed0353884b03a/1606758204847/46527248757.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc2d1048139af037651a389/t/5fc75918bfb90028be4fe8d5/1606899992880/temple_run_3_game_free_play.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbcf5e8b4c4d833b8bcf2e6/1606219240727/magic_circle_against_law_pathfinder.pdfIn PDF document text