Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd98b530e80263b8…

MALICIOUS

PDF

15.2 KB Created: 2020-10-13 23:21:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cbf454ce5c49b1e24a980072448aec80 SHA-1: 2147d4abf68b51c2284059a4469560a5dc15bda9 SHA-256: fd98b530e80263b899ec3e2e7dc68a643814178eb9d91297d90fb7a4baa33dcd
172 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document is designed as an image-based lure, presenting a screenshot to trick users into clicking a link. This link redirects to a malicious infrastructure, likely to download further malicious content. The presence of numerous external PDF links suggests a link farm intended to improve SEO for malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9975

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 15 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=san+tropez+tanner+instructions
    • https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/aa92d.pdf
    • https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/caa64.pdf
    • https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3029889.pdf
    • https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/1000608.pdf
    • https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/1429013.pdf
    • https://site-1036686.mozfiles.com/files/1036686/palovoj.pdf
    • https://site-1041284.mozfiles.com/files/1041284/sopapikevoxulixowifo.pdf
    • https://site-1040129.mozfiles.com/files/1040129/jesab.pdf
    • https://site-1038733.mozfiles.com/files/1038733/13282330863.pdf
    • https://site-1042010.mozfiles.com/files/1042010/22269048854.pdf
    • https://cdn.shopify.com/s/files/1/0494/5929/8471/files/focus_on_life_science.pdf
    • https://cdn.shopify.com/s/files/1/0432/8056/4392/files/clash_royale_deck_builder_for_clan_war.pdf
    • https://cdn.shopify.com/s/files/1/0480/8343/5674/files/87897188538.pdf
    • https://cdn.shopify.com/s/files/1/0432/6513/0658/files/92961222965.pdf
    • https://cdn.shopify.com/s/files/1/0430/6042/8962/files/35603708581.pdf
    • https://cdn.shopify.com/s/files/1/0484/7209/6918/files/vujupanatotetesulan.pdf