Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff167f0e58d8d0f9…

MALICIOUS

PDF

100.6 KB Created: 2020-10-29 22:41:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2c107f74446bafaf712689a01d33af3c SHA-1: 7db50707fd4dee0d3d462a27404535291d22e346 SHA-256: ff167f0e58d8d0f92c3e9cd2686537e8861f94485d262d815c5d26923f65b670
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded links, with a critical heuristic identifying it as a link farm. One of the primary links, 'https://cctraff.ru/aws?keyword=blue+marble+university+wikipedia', is flagged as a malicious redirector. The document's structure and embedded links suggest an attempt to direct users to potentially harmful external content, possibly for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9714

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?keyword=blue+marble+university+wikipedia
    • https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/199877.pdf
    • https://cdn-cms.f-static.net/uploads/4383156/normal_5f9296b7e9772.pdf
    • https://cdn-cms.f-static.net/uploads/4367617/normal_5f8b35bf1cfb6.pdf
    • https://cdn-cms.f-static.net/uploads/4385202/normal_5f99c06224eb9.pdf
    • https://zenovoruzunej.weebly.com/uploads/1/3/4/3/134339910/xifepagejobetuxovori.pdf
    • https://cdn.shopify.com/s/files/1/0486/0300/5086/files/convert_file_to_a4_size.pdf
    • https://cdn.shopify.com/s/files/1/0432/9691/5616/files/21901769477.pdf
    • https://cdn.shopify.com/s/files/1/0432/0185/5646/files/somabek.pdf
    • https://cdn.shopify.com/s/files/1/0495/4973/8136/files/richard_feynman_books.pdf
    • https://cdn.shopify.com/s/files/1/0266/8783/2256/files/lord_of_the_flies_chapter_1-2_study_guide.pdf
    • https://uploads.strikinglycdn.com/files/0a8663b9-d0e1-4ccc-8e80-c8d8b05148df/45039065231.pdf
    • https://uploads.strikinglycdn.com/files/c9f89d04-588b-42f7-ad69-ee763cabca0a/types_of_education_seminars.pdf
    • https://cdn.shopify.com/s/files/1/0430/3162/5882/files/jajazefijujudenadu.pdf
    • https://cdn.shopify.com/s/files/1/0497/8904/2849/files/8004897224.pdf