Malicious PDF — malware analysis report

Static analysis result for SHA-256 174bd5df754fbc88…

MALICIOUS

PDF

69.3 KB Created: 2021-09-04 21:49:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-20
MD5: 16ebbcf8609333621efb59e81f0af0ef SHA-1: 270e254520525760dcfe9b315caf923f67542b80 SHA-256: 174bd5df754fbc8851bbd7665edca862cf0588e2c66e74d36ecdea074a31774d
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document is identified as malicious by multiple heuristics and a machine learning classifier, with ClamAV detecting it as a phishing trojan. The PDF_IMAGE_LURE heuristic indicates it's an image-only document designed to trick users into clicking a link, which is supported by the numerous embedded URLs pointing to potentially compromised websites. These links likely serve as a lure for phishing or to download a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9978

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 69 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://inwebjor.ru/uplcv?utm_term=diagnostico+diferencial+lupus+pdf PDF link annotation
    • https://webgirls-studio.com/wp-content/plugins/formcraft/file-upload/server/content/files/161296bb816ac0---sesunatosonukuluvudaref.pdfIn PDF document text
    • https://likeevent.it/writable/public/userfiles/file/48130901944.pdfIn PDF document text
    • http://ukicda.com/admin/fckeditor_upfiles/file/2021081011331080554.pdfIn PDF document text
    • https://aartipalette.com/userfiles/file/mazofaxiropafaropegeku.pdfIn PDF document text
    • https://saintarseny.ca/sites/saintarseny.ca/files/file/73673515676.pdfIn PDF document text
    • https://svetpoznaniyaonline.ru/wp-content/plugins/super-forms/uploads/php/files/39e1d4aa155da6fee06fb2c37aaaa4a1/16990326031.pdfIn PDF document text
    • http://iamsong.vn/uploads/files/43185125241.pdfIn PDF document text
    • https://akproauto.net/nbloom/fckuploads/file/88300388806.pdfIn PDF document text
    • http://improntediteatro.it/userfiles/files/batokares.pdfIn PDF document text
    • https://www.lightingsolutionsinc.net/wp-content/plugins/super-forms/uploads/php/files/fd79d1a5dbb8876369adccfed27e6fd1/51832924091.pdfIn PDF document text
    • http://autoshiftbid.com/fckeditor/userfiles/file/78431587993.pdfIn PDF document text
    • http://soldresold.com/Shradhdha-Mehra/soldresold/final/ckeditorimage/files/kodipuxizokib.pdfIn PDF document text
    • https://georgiamusicpartners.org/wp-content/plugins/super-forms/uploads/php/files/71c2fe91457e49d940f84c4237971f6c/69570308916.pdfIn PDF document text
    • https://cffcommunications.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/1607b9a3b7fa29---47629070209.pdfIn PDF document text
    • http://www.alfainstal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1609d49708ab56---67222808073.pdfIn PDF document text
    • http://odessahighschool1970.com/clients/7/70/70263b1be1b93b62200e198143f59f20/File/91230574080.pdfIn PDF document text
    • https://expungemyrecordnj.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ec68bc2719---17531669193.pdfIn PDF document text
    • http://fotossc.pl/_files/file/ritiribemuminok.pdfIn PDF document text
    • https://web-sila.ru/wp-content/plugins/super-forms/uploads/php/files/81f2bf29475a7aefea7754b8fbd1e694/69334125558.pdfIn PDF document text
    • https://adbetelparaguay.com/wp-content/plugins/super-forms/uploads/php/files/b76202e5d90966815714cc5aa3b7bef5/9616013812.pdfIn PDF document text
    • https://jgmurphy.com/wp-content/plugins/super-forms/uploads/php/files/13b52d63a6fd07eea568836cfe8544d4/zusoxom.pdfIn PDF document text
    • https://hometeamcorp.com/images/usr/vesixu.pdfIn PDF document text
    • https://israelonthehouse.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080b219f176a---devemirobapedox.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b45c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB45C 10896 bytes
SHA-256: 34dc1bf6fd347bef65d448a5828c56062694abb6e90cb7806e868adb400e05fc
font_01_sfnt_off0000cd7c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCD7C 13828 bytes
SHA-256: 9e0bd0a0663e977fcdcbb76a0b4a623e6e0cc34dfe9a378d19cfb5362bf42c44
font_02_sfnt_off0000ef8f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF8F 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1