Malicious PDF — malware analysis report

Static analysis result for SHA-256 2aec81ccfc4aceaf…

MALICIOUS

PDF

234.3 KB Created: 2021-06-25 12:24:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 1fd9e321d4aba6e7d5e6eee1c62cc37e SHA-1: 734ab23e8a68b19146d4537eea023cb4238a36d6 SHA-256: 2aec81ccfc4aceaf8b3ed15edccc9a7f7916cec55f9b90fc7f9570ab7d404d92
146 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm pointing to multiple compromised WordPress sites, suggesting a phishing or malware distribution attempt. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing. No scripts were extracted, but the presence of multiple external URIs to potentially malicious PDFs is a high-confidence indicator of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9065

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://senzedigicraft.com/wp-content/plugins/super-forms/uploads/php/files/290a3c3433d968fe2a99b47663b5697e/poxakuvivuriti.pdf
    • http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a9db818f9c1---32003626879.pdf
    • http://www.nanodrywash.com/wp-content/plugins/formcraft/file-upload/server/content/files/160878a37b6e1e---venobot.pdf
    • https://evergreencans.com/userfiles/file/lonekogakunofuzevorabadin.pdf
    • http://spy-military-labs.com/userfiles/file/wigogopak.pdf
    • https://allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/7b918c0b6f2c501cb596385c3d82b6eb/kewagidinajamokebipizumo.pdf
    • https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/6b4595cb9c980f2208c8fd8e4b387f63/77995870248.pdf
    • http://iqlacpro.vn/emotive/upload/files/31655116858.pdf
    • https://www.apartamentselsllacs.com/wp-content/plugins/super-forms/uploads/php/files/t6tr931jkumlh8ok5d7sv41bdp/46810610138.pdf
    • http://grupogmec.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ffae9760f9---mininudunavanerolufav.pdf
    • http://reicar.dk/userfiles/file/18551276224.pdf
    • http://www.playerclub.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1606c8151b81a3---84748345849.pdf
    • http://79.170.40.182/boothtastic.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096dd0183f8b---bozomawazuzadajesemuk.pdf
    • http://sllight.ru/design/img/upload/file/24266991806.pdf
    • https://www.projectorrentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a8b1faa3da1---71257412138.pdf
    • http://informerfitness.com/wp-content/plugins/super-forms/uploads/php/files/42ef079f7b5505a5cb03653a135dfc29/23672255237.pdf
    • https://www.landalastadservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cd4d1623f8---70333151367.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/S30rS-6n6vg/uplcv?utm_term=may+2017+sat+answers+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000117f9.bin
1000009579a94b63a731f78b3ddcc66ee4fbbe6fd7277b08d8d0536926fc3da3
pdf-font-stream PDF embedded font (sfnt) at offset 0x117F9 17256 bytes
font_01_sfnt_off000144f9.bin
9d5144547e0b729630886a3ad3ce48e7da84b0115899dd9c2390406af6f0fecd
pdf-font-stream PDF embedded font (sfnt) at offset 0x144F9 16092 bytes
font_02_sfnt_off00015a3e.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x15A3E 16792 bytes
font_03_sfnt_off0001724d.bin
f261b6536fc1530b5bc5d30128dde107410c42215b4203180fa7f2a48c179d56
pdf-font-stream PDF embedded font (sfnt) at offset 0x1724D 217224 bytes
font_04_sfnt_off0003823f.bin
6c784743be4138cc395ed001188d1d49d499461a0db0a0c6a8af29b90351eca0
pdf-font-stream PDF embedded font (sfnt) at offset 0x3823F 10772 bytes