Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9f083f3a6e2785b…

MALICIOUS

PDF

37.6 KB Created: 2020-10-28 22:42:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 93862cabf7483ed0bada690fa243aa34 SHA-1: e85f0f838794c93c12414467e7e68e62f849cf04 SHA-256: e9f083f3a6e2785bc7105b3a73a86e5e0cfa356eafde401316b52769ae39d761
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, indicating a phishing or malware distribution attempt. The ML classifier also flagged the document as malicious. While no scripts were extracted, the presence of a malicious URL is a strong indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6680

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?keyword=iron+man+mark+133