Malicious PDF — malware analysis report

Static analysis result for SHA-256 04b0c83c2ad66b00…

MALICIOUS

PDF

426.0 KB Created: 2021-06-09 13:36:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-24
MD5: 5a226feec9509c8b9825629c33b00670 SHA-1: 98e7b037a3eb7e839d85ccdd33b413bbfba673f6 SHA-256: 04b0c83c2ad66b005d7cb83cafc3993f196fbc3746c5b3a319158e086098e88d
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file that contains numerous embedded URLs, many of which point to compromised WordPress sites. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The presence of embedded URLs suggests an attempt to redirect the user to malicious content or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9840

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://chcial.ru/uplcv?utm_term=percy+jackson+pdf PDF link annotation
    • https://chamsocmuihong.com/wp-content/plugins/super-forms/uploads/php/files/egr0maesv27nutr8q2l0bdn3cl/likibotesosodoxikul.pdfIn PDF document text
    • https://study-go.info/wp-content/plugins/super-forms/uploads/php/files/43bbe0a67e586d344657f658d2dd2d5e/39667113988.pdfIn PDF document text
    • http://goldmustang.com/files/files/wujara.pdfIn PDF document text
    • https://fablab808.com/nbloom/fckuploads/file/60584867050.pdfIn PDF document text
    • https://cananalimdar.com/wp-content/plugins/super-forms/uploads/php/files/o9aten1jhhsonp67d47vp0c2da/daranumuxuzi.pdfIn PDF document text
    • https://abril.pe/wp-content/plugins/super-forms/uploads/php/files/utbskvputvnbjmr585hmbkprio/18880943243.pdfIn PDF document text
    • http://babamoleskine.com/files/file/ritezamuxive.pdfIn PDF document text
    • https://nhaban24h.com.vn/wp-content/plugins/super-forms/uploads/php/files/ngno0eg9546lhb97uph8j1hiut/mutokoradeki.pdfIn PDF document text
    • http://kondicionery-dolgoprudny.ru/upload_picture/file/nunutomeso.pdfIn PDF document text
    • http://tavernadelsnoguers.com/wp-content/plugins/super-forms/uploads/php/files/738b31ff086b305bbe8dc6a7f33b05ab/jamobusirigezatudu.pdfIn PDF document text
    • http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607eeb87ba375---mozeko.pdfIn PDF document text
    • http://www.lauricedale.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160830e3abc891---76946386465.pdfIn PDF document text
    • http://lifestyleufa.ru/wp-content/plugins/super-forms/uploads/php/files/55652892efb1eab7169f848ffa9ed7ff/59399729711.pdfIn PDF document text
    • https://sv-fin.ru/wp-content/plugins/super-forms/uploads/php/files/b18e8223e160a7389456e89688e01e6b/19559149461.pdfIn PDF document text
    • http://www.ibadirect.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bed7420eb35---nivilotazakab.pdfIn PDF document text
    • http://manufim.co.il/wp-content/plugins/formcraft/file-upload/server/content/files/1607c62485eb03---marukeratab.pdfIn PDF document text
    • https://lakecountyoralsurgery.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a315d03be98---85598720348.pdfIn PDF document text
    • https://rmdschoolandcollege.com/wp-content/plugins/super-forms/uploads/php/files/dmidodde6lnm55o2jlj15ph7v3/bewotodagirutodi.pdfIn PDF document text
    • http://thm-holding.ru/wp-content/plugins/super-forms/uploads/php/files/759a972655d682e0701f938e82054eeb/gavusinojirezubugi.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00016104.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x16104 432752 bytes
SHA-256: 0f0626db3d0e7175de418e518be53b5782b4d9c9017d90caaf3ca1b4b066fa92
font_01_sfnt_off00064b62.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x64B62 5360 bytes
SHA-256: c5322fc4d8ef0ca5e2c9e702b0c06b58f1e230ee2275ddc20895d0962453ebc2
font_02_sfnt_off00065dc3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x65DC3 10612 bytes
SHA-256: bb188cf1ad001f184b11d6c2a18b2b95d85c944921ca33379b2ac742be2e4476
font_03_sfnt_off0006826b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6826B 16060 bytes
SHA-256: 309a3b1fceaa03c0c9bd2e8b4443fcfd5b986ddbb92b7334120c253d92888431