Malicious PDF — malware analysis report

Static analysis result for SHA-256 f93537f4cfa8ac81…

MALICIOUS

PDF

52.6 KB Created: 2020-12-23 10:17:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-17
MD5: 91b7421609fb00d33f6597d0e810133b SHA-1: 2f8ae1710f1f0e3a72c1e3abe1005579882ed1e3 SHA-256: f93537f4cfa8ac818af6a44dccac4764175d8ad4f470aa38aa8e045efcad60da
212 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains multiple links, with one identified as a malicious redirector. The document body, though heavily obfuscated, suggests a lure related to music sheets. The presence of numerous external links, including a link farm, indicates a strong likelihood of phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6781

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/aws?utm_term=alhambra+guitar+music+sheet In PDF document text
    • https://cdn-cms.f-static.net/uploads/4463272/normal_5fa4753147ade.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378855/normal_5fbe8ce93ee19.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470960/normal_5fdefc43a5f43.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367277/normal_5f8cfd672a3df.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379846/normal_5faa373f2f1ec.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451028/normal_5fc1fe8d40747.pdfIn PDF document text
    • https://ronabamipiboti.weebly.com/uploads/1/3/4/5/134598089/5459811.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4498678/normal_5fdde9667bfe2.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4375357/normal_5fdd3cc4c0308.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fded23088390d34f38c43e6/t/5fdf7e1a15a11837d0bb4d96/1608482331274/dactyl_publishing_year_6_maths_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/65a7c8cb-8419-460c-a66a-9f88634d38d6/suzuzifez.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc598eda879396864281610/t/5fc68dd8f81c9a2a0c889c23/1606847961652/sovalosulexonudikivejavi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4afa6750-3913-4df0-b0b6-866487c4daec/mokofetokenatuj.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd042172f8b574a0f46162/1606222887094/break_the_ice_games_on_zoom.pdfIn PDF document text