Malicious PDF — malware analysis report

Static analysis result for SHA-256 c531860df6ac76af…

MALICIOUS

PDF

83.6 KB Created: 2020-11-23 12:33:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 0504e9a1344f36389643476dd4253066 SHA-1: a9af55d9dc25de9279acc145f6b0b0011e0625fe SHA-256: c531860df6ac76af3222311f0f3f35f700d817b997838d7e7e5f102974932b54
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing a link to a known malicious redirector. Heuristics indicate it's a phishing trojan, and ML classification strongly supports this. The embedded URL is the primary indicator of malicious intent, likely serving as a lure to a phishing site or a download host for further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9131

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?utm_term=cubensis+b+trip+report In PDF document text
    • https://cdn-cms.f-static.net/uploads/4463266/normal_5fab19f75655e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365570/normal_5f870213132bd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4445866/normal_5fa920c758f0f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417139/normal_5f97ddc5e1b41.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366408/normal_5f888229ad18c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413850/normal_5f9a604ec0942.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4376371/normal_5fbb52f881bf0.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a2133a54-4ede-4fb3-a3e8-c143735ab352/peveraxov.pdfIn PDF document text
    • https://s3.amazonaws.com/dubiditiginowo/cashback_2006_full_movie.pdfIn PDF document text
    • https://s3.amazonaws.com/defipedibe/adestramento_inteligente_2_edio.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1c585b17-f657-4f10-98ce-a788ae5795f2/dewey_decimal_system_games_online.pdfIn PDF document text
    • https://s3.amazonaws.com/mulerux/lodapidomikugexumukojepa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fa0b32e1-d3b6-4918-b01b-3cf05035d306/88976553655.pdfIn PDF document text
    • https://s3.amazonaws.com/fapaga/automation_engineer_job_description.pdfIn PDF document text
    • https://s3.amazonaws.com/tifuwuw/kinunosipod.pdfIn PDF document text