Malicious PDF — malware analysis report

Static analysis result for SHA-256 0fcdc6f514b35ecb…

MALICIOUS

PDF

89.1 KB Created: 2021-09-24 12:26:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-02
MD5: aff101cd62ee860020b7b2ca79b933a4 SHA-1: 88b44bd6dfda7291524a9e9a3cfe65e897787576 SHA-256: 0fcdc6f514b35ecbbd036990c1a9f1302d96c700cbca39ff79bcfcd254a7ec2b
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is identified as malicious by ClamAV and exhibits characteristics of a link farm, with numerous embedded URLs pointing to potentially compromised or disposable hosting. The heuristic 'PDF_SEO_DISPOSABLE_LINK_FARM' indicates a pattern of using small PDFs for link farming, and the 'PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM' points to malicious content hosted on compromised WordPress sites. The presence of these link farms suggests an attempt to direct users to external, potentially malicious, websites.

Machine Learning

  • Nyx PDF Classifier clean score 0.2133

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://wronba.pl/uploads/wysiwyg/file/12181495449.pdf In PDF document text
    • http://szcftz.com/upload/sirebatovamalo.pdfIn PDF document text
    • http://lpsa.cz/userfiles/file/81835143460.pdfIn PDF document text
    • http://uk-finansist.ru/userfiles/file/xusonulojuvedujilato.pdfIn PDF document text
    • https://elemental-ia.com/userfiles/file/pakojurex.pdfIn PDF document text
    • http://petraifevronii.ru/ckfinder/userfiles/files/zetovelalixe.pdfIn PDF document text
    • https://clinicscrm.com/img/files/nemogin.pdfIn PDF document text
    • https://coevent.ru/upload/files/fiwavofazude.pdfIn PDF document text
    • https://airshow-bg.com/file/66697495558.pdfIn PDF document text
    • http://studiotecnicomaglio.it/userfiles/files/49275231859.pdfIn PDF document text
    • http://chicagohalo.com/wp-content/plugins/formcraft/file-upload/server/content/files/161320b546c865---pawotajunifirorasabosam.pdfIn PDF document text
    • http://zatuchlina.cz/upload/file/nowofixoxesame.pdfIn PDF document text
    • https://ateneoarbonaida.com/wp-content/plugins/formcraft/file-upload/server/content/files/16141596e9be31---15304912779.pdfIn PDF document text
    • http://www.pirac.org/wp-content/plugins/super-forms/uploads/php/files/efc18fdcfcb332def0db2027da93dbdb/74046533667.pdfIn PDF document text
    • http://vanillasky-ch.com/images/files/pebenevaruwi.pdfIn PDF document text
    • https://keluargamimpi.com/contents/files/36982507680.pdfIn PDF document text
    • http://xn--90afqerdlt1f.xn--p1ai/admin/ckfinder/userfiles/files/nikumanilarep.pdfIn PDF document text
    • http://leeharringtonhomes.com/userfiles/file/xekevogefumifilavezadeb.pdfIn PDF document text
    • http://www.homefacelifters.com/wp-content/plugins/super-forms/uploads/php/files/086bb51456c2a924b16b6bba7cfab94a/japezusi.pdfIn PDF document text
    • https://macauroommate.com/ckfinder/userfiles/files/87369443584.pdfIn PDF document text
    • http://emeat.ru/var/files/73060414997.pdfIn PDF document text
    • https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/161447c2f4e20f---28855082540.pdfIn PDF document text
    • http://rainternacional.com/userfiles/file/14881825512.pdfIn PDF document text
    • http://npi-management.com/ressource/site-image/files/69084049392.pdfIn PDF document text
    • https://anfauglir.com/images/file/45885381947.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=payment+gateway+integration+in+android+applicationPDF link annotation
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fead.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFEAD 18316 bytes
SHA-256: 405b2061dbd8a12e9d3863bd5961aedb1c28ae3f3d10b9068bfb48a64ba3aef2
font_01_sfnt_off00012f25.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12F25 10892 bytes
SHA-256: 748a634ca1ef54258d48a25252812d34c5a17b83850534dd4f1b7277faa87559
font_02_sfnt_off00014828.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14828 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1