Malicious PDF — malware analysis report

Static analysis result for SHA-256 36df7f41706b8018…

MALICIOUS

PDF

93.4 KB Created: 2021-09-08 06:56:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-16
MD5: 53f08c7edb2e8a19b7ad34f09d50ea32 SHA-1: 5f3399a41ba1f6ed7e8a3d913c0dc953b1ad119d SHA-256: 36df7f41706b801883b0425235ab77c03653845c5e4e26f0ecd6a5d2a8106010
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of links pointing to various websites, many of which are hosted on compromised WordPress installations or disposable domains. This behavior is characteristic of a link farm used to distribute phishing content or malware. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tirthmobile.com/wp-content/plugins/super-forms/uploads/php/files/3osndn0k87uv2nn5oq21nn4c43/34201404371.pdf In PDF document text
    • https://maydongy.com/wp-content/plugins/super-forms/uploads/php/files/qcl74apfr02oj312hhf7g1dl8s/83243011018.pdfIn PDF document text
    • https://landlorddebtadvisory.com/wp-content/plugins/super-forms/uploads/php/files/am7rh4o9atuf3umrmkbqt02rm2/96304710650.pdfIn PDF document text
    • https://fzclicks.com/demo/files/editor/file/422513316.pdfIn PDF document text
    • http://greenbrier101.com/userimages/labadanog.pdfIn PDF document text
    • http://fszhenjia.com/upfolder/e/files/20210717153311.pdfIn PDF document text
    • http://fslawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/puxewupumu.pdfIn PDF document text
    • http://industrialdevices.in/uploads/50265648842.pdfIn PDF document text
    • http://bancasemecanino.com/userfiles/files/fikadilop.pdfIn PDF document text
    • http://federicozucchettiarchitetto.eu/userfiles/files/67289401677.pdfIn PDF document text
    • https://rrrc.us/userfiles/file/tikobatawipadetoxogupik.pdfIn PDF document text
    • https://ailani.org/wp-content/plugins/super-forms/uploads/php/files/f430e72cb37182a575ad992a8acd3ed3/2752474973.pdfIn PDF document text
    • http://www.marcado.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1607a94c80fc37---2217383958.pdfIn PDF document text
    • https://www.arphplumbing.co.uk/wp-content/plugins/super-forms/uploads/php/files/p48qbn1pbjnnssftjv9soo43tv/46093866511.pdfIn PDF document text
    • http://vaynhe.com/upload/files/69706087304.pdfIn PDF document text
    • http://przedszkolenisko.pl/userfiles/file/xavenawisosesibozawur.pdfIn PDF document text
    • https://jcmimoveis.com/userfiles/file/40255926826.pdfIn PDF document text
    • http://timebank.ru/sites/default/files/photos/pagefile/webazosap.pdfIn PDF document text
    • https://mandarinkinesiska.com/userfiles/file/52932104657.pdfIn PDF document text
    • https://kalyna.ua/sites/default/files/userfiles/file/79236862376.pdfIn PDF document text
    • http://princeworldwide.com/multimedia/userfiles/file/42377486942.pdfIn PDF document text
    • http://adoriantarla.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16130eac36f2c0---69848153583.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/3CAf4wW3hvY/uplcv?utm_term=gnosticismo+em+pdfPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ff83.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF83 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off00011795.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11795 21376 bytes
SHA-256: d91b880f91b019989963ffd5f3dad66cdcb3646abbb04c6e9aa2de8eaf8bd2a4
font_02_sfnt_off00014f0f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14F0F 10512 bytes
SHA-256: 4a1b479021bdcfcd66398dad13f1079cb82d9b3f182f7778639d2f1dc4fd8a35