Malicious PDF — malware analysis report

Static analysis result for SHA-256 773878ce39765d91…

MALICIOUS

PDF

105.4 KB Created: 2021-01-10 00:00:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 21ec3de2390e550ecdf203a0c635f113 SHA-1: 4b3b9dae040f506f6fac3e7b682d997c5f275cb0 SHA-256: 773878ce39765d91c36d30e83eb1233a89340d7940fa83d8d7fc13329da4b7b1
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains numerous embedded links, with at least one pointing to known malicious redirector infrastructure (ggtraff.ru). The document body is heavily obfuscated, but the presence of multiple links suggests a link farm or phishing lure designed to redirect users to harmful sites. No scripts were extracted, but the primary attack vector appears to be the exploitation of user trust through deceptive links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9681

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/aws?utm_term=bk+murli+pdf+today In PDF document text
    • https://site-1173325.mozfiles.com/files/1173325/segiveku.pdfIn PDF document text
    • https://site-1172210.mozfiles.com/files/1172210/andor_s_trail_loader_map_editor.pdfIn PDF document text
    • https://duvupobilalef.weebly.com/uploads/1/3/4/6/134630448/8221903.pdfIn PDF document text
    • https://limulepaxot.weebly.com/uploads/1/3/1/3/131379958/xidivivowemujine.pdfIn PDF document text
    • https://site-1168117.mozfiles.com/files/1168117/incredible_monster_stickman_prison_escape_2.pdfIn PDF document text
    • https://site-1168374.mozfiles.com/files/1168374/guvisinalitoxawebunara.pdfIn PDF document text
    • https://site-1178349.mozfiles.com/files/1178349/joriwexamenapifa.pdfIn PDF document text
    • https://site-1174284.mozfiles.com/files/1174284/uno_flip_last_card_rules.pdfIn PDF document text
    • https://site-1168312.mozfiles.com/files/1168312/69904341152.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451363/normal_5fa96555256f8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • https://s3.amazonaws.com/kikunojulejuj/domaxibepobojeza.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bbe7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBBE7 3288 bytes
SHA-256: 89212e3ee011e2623b6bcae505bad8ec3061312f852b8824d6cc2f8eaa69f65d
font_01_sfnt_off0000c7ab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC7AB 5224 bytes
SHA-256: 5d8f99ba1e898fd11862fb76e880f0efd3acb4e2047e36508ae6d16c2ef814cd
font_02_sfnt_off0000d969.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD969 5116 bytes
SHA-256: b3fb3afb007230bd8c933583b6afa7b6c21c3be3cc10a9185e688dddad3f48d9
font_03_sfnt_off0000ea8c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA8C 4944 bytes
SHA-256: 782963801bee74031a5d3dde14c8134c0e0768c1df4b62c2c832a44131b23799
font_04_sfnt_off0000fa9c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFA9C 3048 bytes
SHA-256: e23308bb06bff427f4fe2d795198e016b2e9db23d45fd702446b15ef1a1323d1
font_05_sfnt_off000106a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x106A8 2328 bytes
SHA-256: 6d897259d7ab9db79b0dbb16904cd99ff486aa7f4a475590a5d3e44eab6e0eed
font_06_sfnt_off00011160.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11160 2604 bytes
SHA-256: d4cda5a9ecb2558448f754249352cd4d73a8f7efff03060ee9a54ebf713292d1
font_07_sfnt_off00011c38.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11C38 3840 bytes
SHA-256: 869700f7b438b0b0f23cfbf3a170597ae1a6b01e9ba9f60fe7298d5eefb98f81
font_08_sfnt_off00012a45.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12A45 2108 bytes
SHA-256: b3976ad28991401f3a7e0d936621f3963ed8fd81aff5bedc9e25cf6548b1959b
font_09_sfnt_off0001341a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1341A 4336 bytes
SHA-256: 87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284
font_10_sfnt_off000141b9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x141B9 6640 bytes
SHA-256: c8cb303e765c67f43d6d34f29c1d02953890772ff7b697be779fb29335000f72
font_11_sfnt_off00015362.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15362 11920 bytes
SHA-256: 2a124f4dc30b814a23b91ff2626a5ccfde475009d54944c212d6794974f4dbf8
font_12_sfnt_off00017a4c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17A4C 3536 bytes
SHA-256: 1cc80836e0a54a2c4db1185994f1ac0eab94f7f28d8d60f500043b8ef5b5dd0a
font_13_sfnt_off0001882b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1882B 2608 bytes
SHA-256: d404f64416bf1ff5ad76d6d0ab30c7620aa9735638cfece5436aad8d6ad80edc