Malicious PDF — malware analysis report

Static analysis result for SHA-256 16108cebfa34a3e6…

MALICIOUS

PDF

54.6 KB Created: 2021-09-14 05:01:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: f415c2e97b7b13610bcc1945932ae49a SHA-1: eb4536ff6e87a49e85b90f5df3d715ab7e513517 SHA-256: 16108cebfa34a3e6fc752448909a57c94a1f662a1fab408ba204e7bb2e604a5e
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV and contains numerous embedded URLs that form a link farm. These links point to various domains, many of which appear to be compromised or disposable hosting, suggesting an attempt to obscure the ultimate destination. The presence of 'utm_term' parameters in some URLs indicates a tracking or campaign-related purpose, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.2832

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://infrive.ru/uplcv?utm_term=akira+volume+2+pdf
    • http://servmed.net/userfiles/file/borejawijano.pdf
    • https://diphong.com/uploads/donibaluvoji.pdf
    • http://falconfam.com/ckfinder/userfiles/files/85805572262.pdf
    • https://digireg.sk/upload/kizofoxexugajipus.pdf
    • http://rigassprotes.lv/uploadz/file/vadazolevofagujido.pdf
    • https://www.coconutlodge.com/wp-content/plugins/formcraft/file-upload/server/content/files/16136244935fbd---61692532565.pdf
    • http://balbu.hu/uploads/news/file/42082443708.pdf
    • http://makeyourpartnermelt.com/userfiles/file/lutumevukepibu.pdf
    • http://clarklawtexas.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/febenexatu.pdf
    • http://sobateracota.ro/mm/file/99021585439.pdf
    • https://morethancars.eu/uploads/edytor/file/51923676974.pdf
    • http://www.fullmooneye.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613db7087efcc---tujutimubijofamuwofibare.pdf
    • http://lovesushiscv.com/uploads/files/15141676227.pdf
    • http://thriftstorewebsites.com/flash/thriftstorewebsites.com/file/34925630666.pdf
    • https://mimpishio.com/contents/files/sulufazesomofanizulifovos.pdf
    • https://www.helpfulhunks.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16139ed96c567f---ludoxoxelozomitofilo.pdf
    • http://natur-pet.cz/webpagebuilder/ckfinder/userfiles/files/73390903601.pdf
    • http://orourkelawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/zufibezesaraxezamapu.pdf
    • http://gearcon-eng.com/file_media/file_image/file/34614008761.pdf
    • https://billard-hauri.ch/userfiles/file/79994269777.pdf
    • https://joyfool.art/wp-content/plugins/super-forms/uploads/php/files/0898d1e09f92451032e985ec710fd594/lexawejalojovedukew.pdf
    • http://hoinhikhoavn.com/img/files/96439395952.pdf
    • http://centrlita.ru/archive/image/file/80349475176.pdf
    • http://kimura-shihoshoshi.com/userfiles/file/82016445579.pdf
    • http://www.laterveer-biesenbeek.nl/ckfinder/userfiles/files/guxuvijopoxoz.pdf
    • http://cncforginghammer.com/d/files/bemijawatupinim.pdf