Malicious PDF — malware analysis report

Static analysis result for SHA-256 97b459cba9887cd6…

MALICIOUS

PDF

64.7 KB Created: 2020-11-23 09:39:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1fdb51beb781a8908657dc59c231b5ea SHA-1: 4b76f9a312e4fb49e5eb5dbaedd223f72839c7b3 SHA-256: 97b459cba9887cd60344ec1ed8d93fd3b7b5a65736888e6ae786807bc09c72fd
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing a malicious redirector link to 'ggtraff.ru'. ML classification and ClamAV detection strongly indicate malicious intent. The embedded URL is likely used to lure the user to a phishing site or download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?utm_term=apocalypse+dreams+chords
    • https://rivisoni.weebly.com/uploads/1/3/0/7/130739016/3616183.pdf
    • https://bijufipenonovo.weebly.com/uploads/1/3/4/5/134529550/5847388.pdf
    • https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/902d2b82.pdf
    • https://cdn-cms.f-static.net/uploads/4412599/normal_5fa0a7fbe8251.pdf
    • https://xalipifizipig.weebly.com/uploads/1/3/1/3/131379045/4f044a54.pdf
    • https://cdn-cms.f-static.net/uploads/4369495/normal_5f88437b75847.pdf
    • https://cdn-cms.f-static.net/uploads/4459776/normal_5fbb31634eef7.pdf
    • https://cdn-cms.f-static.net/uploads/4471682/normal_5fb5a5ea44d8f.pdf
    • https://cdn-cms.f-static.net/uploads/4368497/normal_5f9265320edb9.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/megodipewukitoj/container_homes_plans.pdf
    • https://s3.amazonaws.com/jamokaroxoj/manual_ide_eclipse_espaol.pdf
    • https://s3.amazonaws.com/dugibabafod/agreeing_to_disagree.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b49e.bin
1be0cca4d9f1b9ca299d885f0320d12419f5a61694d573de4f5bf53e83edca0d
pdf-font-stream PDF embedded font (sfnt) at offset 0xB49E 4956 bytes
font_01_sfnt_off0000c56b.bin
503ea6931a846e532adef17f97cfea5a6638b241ee84ea6a042d3c7599c6d3f6
pdf-font-stream PDF embedded font (sfnt) at offset 0xC56B 10296 bytes
font_02_sfnt_off0000e857.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0xE857 4324 bytes