Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f6fd5a17b51a0fc…

MALICIOUS

PDF

114.4 KB Created: 2021-07-02 15:22:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 859523ea7cec607f431b39e19148ea84 SHA-1: 2be719824e68fe9f40903ec51ef877317de0467a SHA-256: 0f6fd5a17b51a0fc1410f2ffcd3284ecf3c470564cc3bbb9fffed1231581401c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains a link farm pointing to numerous websites, many of which are hosted on compromised or disposable domains. This behavior is indicative of a phishing or malware distribution campaign, where users are lured to malicious sites. The ML classifier and ClamAV detection strongly support the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9871

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://advicetao.eu/pictures/file/61893239225.pdf
    • http://akinmedical.com/uploads/file/3266361529.pdf
    • https://godparents4tz.org/home/god/public_html/ckfinder/userfiles/files/bokirevitepugoles.pdf
    • http://www.adanakursmerkezi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c1c42700adc---25131634337.pdf
    • https://www.superioreagle.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a81675bc7be---xipoduvagaxobaregaw.pdf
    • https://www.goldenplanet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160ab8bde20164---68992682411.pdf
    • http://wf515345.tw/CKEdit/upload/files/2159030741.pdf
    • https://dispomydeal.com/wp-content/plugins/super-forms/uploads/php/files/6a2a98c8c9be3fbd917d8a11d12c5e9f/vudotujurejiwibatap.pdf
    • https://lllk.ru/wp-content/plugins/super-forms/uploads/php/files/73582b718a2524dfff4c6fde2d75e8ed/53275668127.pdf
    • https://smilepath.com.au/wp-content/plugins/super-forms/uploads/php/files/8eb3ec4951e41ca566d22e18a1dc04d3/58524713883.pdf
    • https://rebates.forex/wp-content/plugins/super-forms/uploads/php/files/9mlkdjdn8h22dc0grkc9ql1om5/66594270873.pdf
    • https://cambodiadriverservice.com/userfiles/file/28746426615.pdf
    • http://mbcasc.net/imgs/file/wemesixigujezipevufulud.pdf
    • https://dispomydeal.com/wp-content/plugins/super-forms/uploads/php/files/30606770131105ddabdd012563d3083f/16625999175.pdf
    • https://sg-design.top/wp-content/plugins/super-forms/uploads/php/files/8ccfc0d28081d5b62785b44737721595/pejajemifunujumalav.pdf
    • https://haps.company/wp-content/plugins/super-forms/uploads/php/files/ec560gfd7rmt1lng1e8uudb507/finenu.pdf
    • https://dongytueduc.com/wp-content/plugins/super-forms/uploads/php/files/jutkq7pavhg98nu0rto1r2671n/68395016770.pdf
    • https://atlastoursntravels.com/userfiles/file/sejijetikeka.pdf
    • http://degeninhotel.ru/admin/ckfinder/userfiles/files/48241661341.pdf
    • http://julieesteban.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609d3893abdf7---xozabaru.pdf
    • https://psychotherapie-dr-albrecht.de/wp-content/plugins/formcraft/file-upload/server/content/files/160bf052ac58fe---45151665311.pdf
    • http://training-solutions.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160bb411392d5b---zanexadokozuwif.pdf
    • http://kapli74.ru/upload_picture/razapivejuvitod.pdf
    • http://steclotildehorton.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16097a5123a2fe---96448184904.pdf
    • https://www.psalighting.com/wp-content/plugins/super-forms/uploads/php/files/699691cbc05b0c96b903c67e1b7d81b9/29623166901.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=vector+form+of+coulomb+law
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00013c9b.bin
7bcdd96d58029556994dd1130d26a05338481d31d3d7c9c93d73fe0af8a6a4c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x13C9B 20692 bytes
font_01_sfnt_off0001739d.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1739D 16792 bytes
font_02_sfnt_off00018bb4.bin
49d17f3dfa58325bd26eb89b9d01e74a130509a717bac9680288a5d7d0b822c4
pdf-font-stream PDF embedded font (sfnt) at offset 0x18BB4 10428 bytes
font_03_sfnt_off0001a376.bin
2ec0af74db8f4302b0410a9be76a1410370674b26b7b3b74451a592e0c00b7cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A376 16460 bytes