Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b3a6168868e0cb0…

MALICIOUS

PDF

68.3 KB Created: 2021-08-13 14:00:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-11
MD5: 232b2333105f64d1c08a4293b7510fe6 SHA-1: 59ddfb0c45e3f0f287a70785f5aa4fda7302b247 SHA-256: 1b3a6168868e0cb06380673d5fe2d0068fe42c63a5c7f278652483b4def8df85
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a PDF document detected as malicious by ClamAV and an ML classifier. It contains numerous external links, many hosted on compromised CMS platforms, suggesting a link farm designed to redirect users to malicious sites. The presence of embedded URLs and the nature of the heuristics indicate a phishing or malware distribution attempt, likely initiated via spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8303

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://inwebjor.ru/uplcv?utm_term=sap+hana+operations+and+administration PDF link annotation
    • http://bayzones.com/fckeditor/editor/filemanager/connectors/php/userfiles/file/57687898279.pdfIn PDF document text
    • https://allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/8363e726b510ecc48b187f64fca04e29/fetanorafenufinenozojoz.pdfIn PDF document text
    • http://www.abcklima.hu//data/editorfile/tofafiperoken.pdfIn PDF document text
    • http://119hero.kr/userData/board/file/50632753492.pdfIn PDF document text
    • https://carstenrath.com/wp-content/plugins/super-forms/uploads/php/files/eq90ckmpah0ocfmobtsbhm0j42/17194915491.pdfIn PDF document text
    • http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160d8960a7b27b---19398294691.pdfIn PDF document text
    • http://dmn.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1607a1b1d43d76---sofoxotugajeni.pdfIn PDF document text
    • http://bagumul.com/file_upload/spaw_upload/file/20210720124632.pdfIn PDF document text
    • https://www.golddustdental.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a8c4daa9848---41689134409.pdfIn PDF document text
    • http://www.optionassurance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160803b0ed0579---ximowifo.pdfIn PDF document text
    • http://bilagroup.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608bb4f486468---firuwadoxe.pdfIn PDF document text
    • https://finestblogger.de/wp-content/plugins/super-forms/uploads/php/files/gu3vofv81bgenc0bpvup15dbi7/98374495644.pdfIn PDF document text
    • https://altonika.pro/files/fck/file/semebinel.pdfIn PDF document text
    • http://4reality.cz/userfiles/files/sulof.pdfIn PDF document text
    • https://charterfori.ir/basefile/charterforiir/files/mubamebusujovipej.pdfIn PDF document text
    • https://www.kadeavenue.com/wp-content/plugins/super-forms/uploads/php/files/8eebc922be5631bf3f821d6809835641/rufudozapelonelozesaroxip.pdfIn PDF document text
    • https://vaitinhdien.com/app/webroot/upload/files/banarew.pdfIn PDF document text
    • https://erdemlerkoleji.com/resimler/files/tepudavuxedagisoputupuzi.pdfIn PDF document text
    • http://s-privod.ru/userfiles/file/nozosejetaxex.pdfIn PDF document text
    • http://davidlbrooks.com/clients/868292/File/39344352169.pdfIn PDF document text
    • http://aiskreunion.com/clients/b/b4/b417c2091670ce0b0d78f4b231aea02c/File/98568986597.pdfIn PDF document text
    • https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606efa3601d2a---98450816411.pdfIn PDF document text
    • https://cabsfromheathrow.com/userfiles/file/lamogofekigibilepokini.pdfIn PDF document text
    • http://vegasoft.hr/wp-content/plugins/formcraft/file-upload/server/content/files/160bfb6f7b304c---basopuvowe.pdfIn PDF document text
    • https://www.prowallpanama.com/wp-content/plugins/super-forms/uploads/php/files/271aeb687d65c2fc630451f1fc4fae6a/lamawotevazufazemakifaf.pdfIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d5ee.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD5EE 17576 bytes
SHA-256: b6d05ed97ebae93f003a89e40142fee26c4b93c869ce53f32ac3a4ed851211a8