Malicious PDF — malware analysis report

Static analysis result for SHA-256 01fcaa784b2955c6…

MALICIOUS

PDF

87.0 KB Created: 2021-07-14 05:05:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-16
MD5: 273a7d3c47053def53bcd7a6bf130bc0 SHA-1: e2613828c0ecd13447177b259b95e4ea255cb228 SHA-256: 01fcaa784b2955c6f43f8056865c61007eeb0d63e63e2c0e9ebe774367a3dfa6
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file was flagged by ML classifiers and ClamAV as malicious. It contains a link farm pointing to numerous compromised websites, indicating a phishing or malware distribution attempt. The document body is heavily obfuscated and unreadable, suggesting it's not intended for user interaction but rather to host these malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9952

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://residenceraffaellotorino.com/userfiles/files/85251583838.pdf In PDF document text
    • https://pinotcar.com/wp-content/plugins/super-forms/uploads/php/files/e67708fc9ebf55aaf77b14c8f2ba99a2/fejagorix.pdfIn PDF document text
    • https://tucsonhomewindowtint.com/wp-content/plugins/super-forms/uploads/php/files/ef56df3c333ac0e207cbc46a060d883b/bodejaxunoxojojax.pdfIn PDF document text
    • http://patronusalapitvany.hu/public_html/upload/42348228942.pdfIn PDF document text
    • http://open.ua/uploads/ckeditor/files/zenerisakorotuwotoj.pdfIn PDF document text
    • https://szekszardportal.hu/userfiles/file/padinanisifawe.pdfIn PDF document text
    • https://www.web2business.pt/wp-content/plugins/formcraft/file-upload/server/content/files/160c253e376d6f---32138913349.pdfIn PDF document text
    • https://gift-edu.ru/wp-content/plugins/super-forms/uploads/php/files/f257e0e160c9f2fb5e2876464336a4d6/jesawulej.pdfIn PDF document text
    • http://janandpoos.com/clients/872640/File/merasoses.pdfIn PDF document text
    • http://www.pirac.org/wp-content/plugins/super-forms/uploads/php/files/84d477afeb367f01faf779a70707b0c0/52212465779.pdfIn PDF document text
    • http://yesilderecine.com/admin/editor_resim/file/6785146700.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608700e9590c7---vatufitovin.pdfIn PDF document text
    • https://greenturtleproductions.com.au/wp-content/plugins/super-forms/uploads/php/files/46306780fd8a2c765f25797c0c56f6a0/jovegabadipukaxegulus.pdfIn PDF document text
    • https://www.toptalentusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a23f44382bd---34769725658.pdfIn PDF document text
    • http://footstepfloor.com/upfiles/files/71094257154.pdfIn PDF document text
    • https://refour.dk/wp-content/plugins/super-forms/uploads/php/files/02cfb9a3a322411946a42d47cdf1a23a/zebutamariku.pdfIn PDF document text
    • https://www.hed-endo.hr/wp-content/plugins/formcraft/file-upload/server/content/files/160898707c5124---paropuzanekeneva.pdfIn PDF document text
    • http://zhodnoceni-penez.cz/is/images/FCKeditor/File/pojara.pdfIn PDF document text
    • http://www.adanakursmerkezi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ba60fc61f29---tuwajubexumafaw.pdfIn PDF document text
    • http://villa-carlshorst.de/sites/default/files/file/nifelizebuxamul.pdfIn PDF document text
    • https://doganagolosa.it/file/21332691957.pdfIn PDF document text
    • https://shayangroup.net/wp-content/plugins/super-forms/uploads/php/files/02ebac10e32024ee84b3702a8663862e/71569522115.pdfIn PDF document text
    • http://www.morenoroofing.com/wp-content/plugins/formcraft/file-upload/server/content/files/160da24d5cb65a---52677691368.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/DOqCt-cVA4I/uplcv?utm_term=numbers+to+written+formPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0dc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF0DC 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off000108f3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x108F3 10468 bytes
SHA-256: f41c01d263f94cd39148d130100dc6e04448fbeab7daeb9f2af21dd3a53044d8
font_02_sfnt_off000120cb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x120CB 17604 bytes
SHA-256: dceed9742fb3bb25207dabd5d1f1e6a093e84e65cf5f73c40041be3ae8302777