Malicious PDF — malware analysis report

Static analysis result for SHA-256 175764d30d5d287b…

MALICIOUS

PDF

88.3 KB Created: 2021-06-28 21:30:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 18a7000a67e34c36ad6aebc02ddf5772 SHA-1: 89050260b1ae173cba5e930cba773c40782633dd SHA-256: 175764d30d5d287bd6de25ecbffbae40f915c364eca54c3f8ff65a88067656c7
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was detected as malicious by ClamAV and exhibits characteristics of a fake CAPTCHA lure, designed to trick users into interacting with the document. The document contains numerous links pointing to compromised WordPress upload directories, suggesting it is part of a link farm used to distribute malicious content. While no scripts were directly extracted, the presence of these links and the fake CAPTCHA heuristic strongly indicate an attempt to deliver a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9947

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16095ecd39c9dc---66506675686.pdf
    • http://madmojo.com/fckupload/file/62648901455.pdf
    • https://www.dyna-tech.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160ce5a600557f---52046277370.pdf
    • https://neoville.ru/wp-content/plugins/super-forms/uploads/php/files/539aaf4f001f04055b703297d12fe4bc/36746946746.pdf
    • https://gpuhub.net/wp-content/plugins/super-forms/uploads/php/files/o23mgfkjoo5rmlauh9olg9e4kh/xikigesolopamumen.pdf
    • https://frontiersneurophotonics.org/wp-content/plugins/formcraft/file-upload/server/content/files/1/16084c4452e643---49009026008.pdf
    • http://www.kmclogistics.com/wp-content/plugins/super-forms/uploads/php/files/447fc58fdd9f61aa5efeffa19e376f9a/30640392902.pdf
    • https://allcreaturesinc.com/files/files/numopumusasuxagafare.pdf
    • https://jfefood.com/wp-content/plugins/super-forms/uploads/php/files/e0924cd41b9393a68bead19d1a3ed711/42391893434.pdf
    • https://www.mercedesbenzofaustinservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c43690a5016---gifizepebiwelo.pdf
    • http://www.louthadventures.ie/wp-content/plugins/formcraft/file-upload/server/content/files/1607f61427fa3f---vabawijuzum.pdf
    • http://wbbray.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c315dd61c61---gejiwowifisalijevikuba.pdf
    • http://www.neslihanonur.com/wp-content/plugins/super-forms/uploads/php/files/08000728c011ffe4979ad456252285d0/jebuledidozolim.pdf
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086c3256309e---deputitumamajinunalipi.pdf
    • https://goldenparadisestsimons.com/wp-content/plugins/super-forms/uploads/php/files/7fa00f0fc44c29dbacb8045233875d95/46551058282.pdf
    • http://bjjiffy.com/upload/zakewuzodurife.pdf
    • http://www.highlandmetals.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160c670bd91a4b---ravirivumokajekavevap.pdf
    • https://otartufo.com/ckfinder/tartufofiles/files/10757673521.pdf
    • https://anandamsanyal.com/userfiles/file/30921207782.pdf
    • http://baliretreatcenter.com/olabali_ci/media/images/newsfiles/kelanerelafapanowenemu.pdf
    • https://www.avenueroadadvertising.com/wp-content/plugins/formcraft/file-upload/server/content/files/160743520767b6---lunaxajebikozakujopikos.pdf
    • http://contentworks.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1606d2e214d52c---zejol.pdf
    • https://bodwellassociates.com/wp-content/plugins/super-forms/uploads/php/files/40f5fa25f9a9edc90550bb2768355672/39841247158.pdf
    • https://iescolumbus.org/wp-content/plugins/super-forms/uploads/php/files/4c187d5381236c6616bf6bbeb34af65c/11712254487.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/FevRqgeaUVY/uplcv?utm_term=discord+groups+for+gamers
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f4fc.bin
0bbae41fa65d45aee8941f9a546d576872ee6451beff04bd4477924cbed3c523
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4FC 10816 bytes
font_01_sfnt_off00010dbd.bin
1d2ee3c6604703efa2d83bb1c4c5f7f0b2973f0a9d3a73fe25f6797ede680f19
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DBD 17536 bytes
font_02_sfnt_off00013c14.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x13C14 16792 bytes