Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdb0a6b56b7f3fd2…

MALICIOUS

PDF

15.2 KB Created: 2020-11-04 13:47:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 49c95f22046433bd432832f38bc1fcae SHA-1: cef2288007fa9030cd38eadaa1a7d65e9edac0f2 SHA-256: cdb0a6b56b7f3fd221023d48b3d19eefac54de63e26139e03e50a359df7d72b0
112 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF is designed as a lure, presenting an image that likely conceals a malicious link. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' confirms that the embedded URL, 'https://ggtraff.ru/strik?keyword=tv+shows+apk', leads to known malicious redirector infrastructure. The document's small size and image-only nature further support its use as a phishing or malware distribution tool.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9972

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 15 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?keyword=tv+shows+apk
    • https://cdn-cms.f-static.net/uploads/4365570/normal_5f88658035388.pdf
    • https://cdn-cms.f-static.net/uploads/4376369/normal_5f8df0de6116d.pdf
    • https://cdn-cms.f-static.net/uploads/4391047/normal_5f9888b798008.pdf
    • https://cdn-cms.f-static.net/uploads/4369626/normal_5f9bebc93a7c9.pdf
    • https://cdn-cms.f-static.net/uploads/4373987/normal_5f9a62e392194.pdf
    • https://cdn-cms.f-static.net/uploads/4372371/normal_5f89a0bbb9614.pdf
    • https://uploads.strikinglycdn.com/files/860e2a96-d8d2-4155-9ff2-cb10b89bc1d2/dizeromisaj.pdf
    • https://uploads.strikinglycdn.com/files/36e7d69e-822a-46d4-a413-01bc4e9dc56c/29785225167.pdf
    • https://uploads.strikinglycdn.com/files/80b6fff8-6439-4adc-a1dc-abc5a5c4d1f7/tattletail_game_free_no_download.pdf
    • https://uploads.strikinglycdn.com/files/8861c6dd-5d4b-42a9-baf4-56ffca9a408b/punto_y_aparte_5th_edition.pdf
    • https://uploads.strikinglycdn.com/files/db051c44-ad5b-4fb7-8e6f-ca022d89a103/toni_morrison_jazz_novel.pdf
    • https://uploads.strikinglycdn.com/files/090cdb89-5d05-4900-bbc0-0b60d4db89c6/reletiridunenad.pdf