Malicious PDF — malware analysis report

Static analysis result for SHA-256 13690ca5ef9569fa…

MALICIOUS

PDF

49.6 KB Created: 2020-11-17 00:23:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cd4a3e8c3b3e7047f52bbaf412725f73 SHA-1: bca72c09e11d2d8a61262da5425ef627f4193a48 SHA-256: 13690ca5ef9569fa060910cfd78200ab041acb1f98550d174d9aea503b02a5ca
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a critical heuristic firing indicating a malicious redirector link to 'https://ggtraff.ru/strik?utm_term=forever+chords+ukulele'. The ML classifier also flagged the document with high confidence. While no scripts were extracted, the presence of a malicious URL strongly suggests a phishing or malware delivery attempt, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8694

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?utm_term=forever+chords+ukulele
    • https://cdn-cms.f-static.net/uploads/4407781/normal_5f9ebba6638cf.pdf
    • https://cdn-cms.f-static.net/uploads/4494160/normal_5fafe0f9d43a1.pdf
    • https://cdn-cms.f-static.net/uploads/4394066/normal_5f9bb154ad865.pdf
    • https://cdn-cms.f-static.net/uploads/4380090/normal_5f8eef1b0cd3b.pdf
    • https://uploads.strikinglycdn.com/files/ea6c2098-7aad-4a5f-a7a4-94c4bd81b52f/smash_bros_ultimate_soundtrack.pdf
    • https://s3.amazonaws.com/navoburarovada/lowrance_elite_3x_fishfinder_owners_manual.pdf
    • https://s3.amazonaws.com/ganubifirigevi/balancing_chemical_equations_worksheet_science_spot.pdf
    • https://uploads.strikinglycdn.com/files/3b6d4132-c61d-4d4c-a1b9-f1e9836afdd2/fupazoludepu.pdf
    • https://s3.amazonaws.com/defujo/91812045542.pdf
    • https://s3.amazonaws.com/fasanag/lucknow_university_bsc_chemistry_syllabus.pdf
    • https://s3.amazonaws.com/bejideba/51348754964.pdf
    • https://uploads.strikinglycdn.com/files/40b3800a-48b6-42f8-992e-b25bd9c5f116/mivevododuvodevobivokati.pdf
    • https://s3.amazonaws.com/kiwopusafize/vanuwiwerudizomovigituj.pdf
    • https://uploads.strikinglycdn.com/files/68395162-5e9c-49c0-8486-7f0343a993e8/kelobubeme.pdf
    • https://s3.amazonaws.com/xesigeze/grundy_county_tn_sheriff_department.pdf
    • https://uploads.strikinglycdn.com/files/5dcf2552-bc35-4150-a192-2166c42e111d/clear_glasses_frames_near_me.pdf