Malicious PDF — malware analysis report

Static analysis result for SHA-256 054b5674e91e981d…

MALICIOUS

PDF

77.9 KB Created: 2020-11-09 03:27:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a204c5cf1ba35b79f3be65e2b623226 SHA-1: 1166edc533b268e9ef3bcfc09a09bd00b2a949a7 SHA-256: 054b5674e91e981d83e43ab2ebf31aa5b5812b566eb48c67864d7781c7f0390e
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, ggtraff.ru, which is highly indicative of malicious intent. The ML classifier also strongly flagged this PDF as malicious. While no scripts were explicitly extracted, the PDF structure itself contains embedded URLs and link actions that point to potentially harmful content, suggesting a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?keyword=monte+carlo+excel+model
    • https://cdn-cms.f-static.net/uploads/4389074/normal_5fa875ac99007.pdf
    • https://cdn-cms.f-static.net/uploads/4426424/normal_5fa161a00a204.pdf
    • https://watalixajine.weebly.com/uploads/1/3/4/6/134635748/kanogugevamesizo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://binunix.files.wordpress.com/2020/11/12245582438.pdf
    • https://s3.amazonaws.com/penale/how_often_to_renew_tlc_license.pdf
    • https://s3.amazonaws.com/salosibejodod/guide_to_tarot.pdf
    • https://nosajal.files.wordpress.com/2020/11/pretrito_imperfecto_de_subjuntivo_ejercicios.pdf
    • https://s3.amazonaws.com/jazuravazaguz/evendale_eagles_swim_team.pdf
    • https://s3.amazonaws.com/xabalaru/aranmula_vanchipattu.pdf
    • https://noduvan.files.wordpress.com/2020/11/42913726097.pdf
    • https://baginalikut.files.wordpress.com/2020/11/macan_2019_owners_manual.pdf
    • https://lamopute.files.wordpress.com/2020/11/edward_said_culture_and_imperialism_chapter_2_summary.pdf
    • https://rupuxijod.files.wordpress.com/2020/11/22449567177.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000f742.bin
c0972892e6ace21156768eb7d2fc9b3f80f50557c0252317c499cd7367447f69
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF742 29428 bytes
font_00_sfnt_off0000b700.bin
1a8316466ab48ba6b258dcaf25e323e99b7ccd9e82298c6f3c7b324e72f21105
pdf-font-stream PDF embedded font (sfnt) at offset 0xB700 4980 bytes
font_01_sfnt_off0000c7de.bin
a36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620
pdf-font-stream PDF embedded font (sfnt) at offset 0xC7DE 1800 bytes
font_02_sfnt_off0000d06b.bin
b133faa8dad6e03ab97bb1916e4f9ba1ca0686aa608e82802be2eafe51e57f48
pdf-font-stream PDF embedded font (sfnt) at offset 0xD06B 11344 bytes