Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f412a2d36dce25c…

MALICIOUS

PDF

176.6 KB Created: 2021-06-11 01:27:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: dfff5da1cff20adab9a965157b126ebb SHA-1: 438fef1c3bc1d5da29c7bc1aca38124b4c4eb2fe SHA-256: 0f412a2d36dce25ca3d247c2e9f2a32e48207dd8d1da00cd5f9b0ec2d368baeb
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains numerous links pointing to compromised WordPress uploads and disposable hosting, suggesting a phishing or malware distribution campaign. The embedded URLs like 'https://catamma.ru/uplcv?utm_term=instagram+stories+anonymous+online' are likely used to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9523

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://catamma.ru/uplcv?utm_term=instagram+stories+anonymous+online PDF link annotation
    • https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/dfb1e7d47f83ea4bb28cf86984835e1e/44925830859.pdfIn PDF document text
    • https://samiznojmo.cz/wp-content/plugins/super-forms/uploads/php/files/b97167d2e8ccb38e7e808c01cb3d3fc6/mesixozemotufoj.pdfIn PDF document text
    • https://camile.vn/wp-content/plugins/super-forms/uploads/php/files/u30iqpvd79cfs7dgss7np28718/vusubowafaxowe.pdfIn PDF document text
    • https://halobysciton.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080ce7fa0117---bipinigiwutifi.pdfIn PDF document text
    • http://amtusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/16087a063a8709---70704922904.pdfIn PDF document text
    • http://travisreunion.com/clients/1/1d/1d9c560ef9ee6310b862f4c9d288d7bd/File/17653502509.pdfIn PDF document text
    • https://deltagroup.bg/uploads/file/52535855241.pdfIn PDF document text
    • https://designcoordinators.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607fb2ca5ab47---murunoxakitulu.pdfIn PDF document text
    • http://anvlaw.com/userfiles/file/53607522204.pdfIn PDF document text
    • https://www.amiunaorchestra.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1606ccc610d653---jozaroge.pdfIn PDF document text
    • https://alternativecarrepair.com/userfiles/file/36745633258.pdfIn PDF document text
    • https://robertmatzuzi-massagetherapist.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160a0becd07aa9---66987533219.pdfIn PDF document text
    • https://cedarcreeksauce.com/wp-content/plugins/super-forms/uploads/php/files/7a7946376d4e55d5b8cc69d8949ba484/zadomogawuwokoman.pdfIn PDF document text
    • https://antoinepanau.com/wp-content/plugins/super-forms/uploads/php/files/1cf7cbea04660bc0e9c57a9e872155cb/21314315018.pdfIn PDF document text
    • https://postscriptproductions.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bfa64135e35---17602895014.pdfIn PDF document text
    • https://qualitycountscleaning.com/wp-content/plugins/super-forms/uploads/php/files/b5b3e01dda7f91f7368fe9c93073bc25/13441465550.pdfIn PDF document text
    • http://www.annaleehuber.com/content_files/file/torakusubekev.pdfIn PDF document text
    • http://www.oknookna.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160720b39a6931---39390267755.pdfIn PDF document text
    • http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609d35dabff05---numijebotife.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0001528a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1528A 88068 bytes
SHA-256: a772f380e9886c6eb73ab4290a7f69e1d137041354be913c4ddbd38ffd1ab096
font_00_sfnt_off0000ec9e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC9E 13164 bytes
SHA-256: 6ac9e27338b0d9bb758cb5b2ddf28257813e2a27b06ddc4539a9ad4d8debf234
font_01_sfnt_off0001115a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1115A 14548 bytes
SHA-256: f4f2048432889b1b9e73a8ff8270949f67e01cb0fccc841c126ab31356fa2610
font_02_sfnt_off00014174.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14174 5044 bytes
SHA-256: 0f2be0d9d2a4f6ed85a87768b9c927bd7cb9b62a27a23448e17bd848a783a5ab
font_04_sfnt_off00023d57.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23D57 5812 bytes
SHA-256: ac46ee95c0fa6e3a7d391a0d808f02bfdea0c489ddbd44b21f539b2961f851a0
font_05_sfnt_off00024bf0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x24BF0 17812 bytes
SHA-256: 193e7c4839630677020c86783ac22a23b8c0f04292894e29b4cb847035f2fd24
font_06_sfnt_off0002817e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2817E 22192 bytes
SHA-256: a76240c216256d7e833c8d3ec2a7d8a6f7bf16dba12ca00d7b53ef0f6beab806
font_07_sfnt_off0002a831.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2A831 1752 bytes
SHA-256: 67470589e40c7db1288ffadf7c2c566778eec73a0d27cdc44437c8436fa9b068