Malicious PDF — malware analysis report

Static analysis result for SHA-256 07b3d649fac89012…

MALICIOUS

PDF

89.7 KB Created: 2021-07-28 00:32:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-22
MD5: 0d288d0dbb7f734481f85e25c4602795 SHA-1: b265ea9a0665a2e14d299b8bd770e6f2db01212d SHA-256: 07b3d649fac89012882b67e49b755b4ff072f9907f05d2d6ffd6282badc876fe
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is identified as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It functions as a link farm, directing users to numerous compromised WordPress sites hosting further PDF files, suggesting a distribution network for malicious content. The presence of PDF-specific heuristics like 'PDF_SEO_DISPOSABLE_LINK_FARM' and 'PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM' reinforces this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://web-sila.ru/wp-content/plugins/super-forms/uploads/php/files/afb41ff59c705ca8302e126393e9593d/lalitejikovode.pdf In PDF document text
    • http://svenstavik.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f2495a02cc---66195607107.pdfIn PDF document text
    • http://www.tecnotrefg.it/wp-content/plugins/formcraft/file-upload/server/content/files/16092432c1db45---gadajokagimopiziwodadog.pdfIn PDF document text
    • https://laneopx.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609ed4c86bebe---sulesakazisubopofajof.pdfIn PDF document text
    • http://paymentsbusiness.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160d0a62b080e6---tugisakagirutagivonito.pdfIn PDF document text
    • https://www.schroedersales.com/wp-content/plugins/super-forms/uploads/php/files/bb134c9c5be3cc4aef41244a7a258968/71399007240.pdfIn PDF document text
    • http://hoaisonland.vn/upload/files/36911789134.pdfIn PDF document text
    • https://alphacleanwashing.com/wp-content/plugins/super-forms/uploads/php/files/4878f5100903aefa603bf8b0ec760ac9/zegujatozademufufu.pdfIn PDF document text
    • https://realestateconnect.us/wp-content/plugins/super-forms/uploads/php/files/1vjnqj66269k15lm068mu0qcb5/61055201681.pdfIn PDF document text
    • http://geose.ru/userfiles/file/23850325687.pdfIn PDF document text
    • https://dungcuruamui.com/wp-content/plugins/super-forms/uploads/php/files/v9ipg570frfmpg0f271q8iqf6n/kobanelimatiwu.pdfIn PDF document text
    • http://makingtheturngolf.com/clients/9/92/925d9bae4ecf380f28dbe0e1390c16eb/File/timete.pdfIn PDF document text
    • http://stylekd.ru/files/zovufizedeb.pdfIn PDF document text
    • https://beaumont-residence.com/wp-content/plugins/super-forms/uploads/php/files/7jthasgp8dskpbfd812hsjkser/rizademebid.pdfIn PDF document text
    • http://foodchemsino.com/d/files/tipaxivoxiso.pdfIn PDF document text
    • https://leavereview.com/customerinterview/ckfinder/userfiles/files/58828752975.pdfIn PDF document text
    • http://www.assignproject.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f97dc4b63e---66745515420.pdfIn PDF document text
    • http://kistours.hu/userfiles/file/91062849526.pdfIn PDF document text
    • http://bluecars.pl/userfiles/file/ratomap.pdfIn PDF document text
    • https://maryamghiasi.com/images/upload/files/fukoku.pdfIn PDF document text
    • http://elyriahigh1974.org/clients/0/05/052ab20d644b737728595af1a47b4450/File/vofowul.pdfIn PDF document text
    • http://gennarimaq.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160aae2c07ab96---nelukumamefujamoz.pdfIn PDF document text
    • http://www.elsecretodelolivo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f179e6263c---patiwumomivemakuniw.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/S30rS-6n6vg/uplcv?utm_term=how+to+heal+a+toenail+removalPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fe91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFE91 10348 bytes
SHA-256: 204949b7c39deee21f1031b9cea091217123d3d8db1805e857328ff4f3d0f466
font_01_sfnt_off000115b0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x115B0 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00012dc2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12DC2 16668 bytes
SHA-256: dcc0014032776362183b45e47c2b24937d0877ed62b4e15072005baa9d695a80