Malicious PDF — malware analysis report

Static analysis result for SHA-256 08305fc59b5ada59…

MALICIOUS

PDF

87.2 KB Created: 2021-05-10 02:43:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 869d47a908bbe7dd362198c93045b55f SHA-1: b345cdf783226e10d8c8449f5504a44e5a980f59 SHA-256: 08305fc59b5ada595489009e7571c1f48411b7d729494894826839c5d3a1424b
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains numerous links to external websites, many of which are hosted on compromised WordPress sites. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The embedded links suggest an attempt to redirect the user to malicious content or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crewmak.ru/uplcv?utm_term=mhw+behemoth+lance+guide
    • https://nicemexico.net/wp-content/plugins/formcraft/file-upload/server/content/files/16083ab59aee41---nexulinugomofifuwirudole.pdf
    • https://betonwerkendejonge.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1606d84f542832---83002218454.pdf
    • https://independentmusicleague.com/wp-content/plugins/super-forms/uploads/php/files/da48f49051d1c0842d2f247054f3b808/kevepupamajomujadijixirem.pdf
    • https://thriveelearning.com/wp-content/plugins/super-forms/uploads/php/files/ac815a52e5b0a1167a5cabf0d8f5d6ae/pelozikejupewadarumon.pdf
    • https://controlcert.se/wp-content/plugins/formcraft/file-upload/server/content/files/160771c99c84e6---batowiroxexusi.pdf
    • https://alignerco.com/wp-content/plugins/super-forms/uploads/php/files/d91db589fde6c42baa11d3b5c8a31102/1397433432.pdf
    • http://plenaadoracao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16097fe423ef13---wilozesoxujirobojafewatu.pdf
    • http://www.patricktennis.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607b9705dee54---65832442363.pdf
    • http://recamonde.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1606fc71170968---xetavewobulubexofuro.pdf
    • https://stpetejazz.com/wp-content/plugins/super-forms/uploads/php/files/c5bu5plro1iuiln4l7jm35g47k/98450004287.pdf
    • https://absolut-fit-and-dance.de/wp-content/plugins/super-forms/uploads/php/files/req1p5bsacnjjt6fkdhtkhiega/roser.pdf
    • https://www.hdontheroadnapoli.it/wp-content/plugins/formcraft/file-upload/server/content/files/16073935921784---699089652.pdf
    • https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/168a6b0d169d91cad48cf0cadb48c7fb/38727822677.pdf
    • http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/t2bsfqr8ur1s7clrn499cn0da0/34481133807.pdf
    • https://diversifiedhumansolutions.com/wp-content/plugins/super-forms/uploads/php/files/b9afb5943933a823cbab8920f694bc38/92082351826.pdf
    • https://aimara-bg.com/userfiles/file/77917839024.pdf
    • https://maspacientes.es/wp-content/plugins/super-forms/uploads/php/files/vjln9cspu1tub3ee5n7uuf2an1/gafaxomujeguzuwenegobej.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f6cf.bin
68d094faf81d2ea9f62e68ee4e789e40b6192f27e323b9e50c58fbaa8f881837
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6CF 2900 bytes
font_01_sfnt_off00010112.bin
356cc73ac6acf70a44b9a7c6b1de025af5e0868b4920500db3062ddf167924eb
pdf-font-stream PDF embedded font (sfnt) at offset 0x10112 5316 bytes
font_02_sfnt_off00011318.bin
a8e67f41caf85bc5c6cdda75691286022791933ae521bd0f540f3828b4a8e2e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x11318 10832 bytes
font_03_sfnt_off00013833.bin
59346cc0df1366d1ba554e939e9bca7cc8121fe97411fd00b0b61f498de12cd6
pdf-font-stream PDF embedded font (sfnt) at offset 0x13833 16556 bytes