Malicious PDF — malware analysis report

Static analysis result for SHA-256 37d671c3c4b6ac79…

MALICIOUS

PDF

86.3 KB Created: 2021-08-17 04:45:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-26
MD5: d9fcc6d6464a432951396878e0b53742 SHA-1: 32a7fe85f02e30c1083887c67bb5c07fb5600256 SHA-256: 37d671c3c4b6ac796a3b903ded6c8cbbb16d21788a08eebf89af25753e933f86
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and an ML classifier indicated a high probability of maliciousness. Numerous heuristics indicate the PDF functions as a link farm, directing users to various compromised websites and potentially malicious files hosted on disposable domains. The presence of external URIs and links to IP addresses further supports a malicious intent to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.zav-mito.si/wp-content/plugins/formcraft/file-upload/server/content/files/1608a72f481a53---84546940066.pdf In PDF document text
    • http://nitexprofi.cz/userfiles/file/pokazuwa.pdfIn PDF document text
    • http://architettosbaffo.com/userfiles/files/xedelo.pdfIn PDF document text
    • http://abcbyspu.com/ckfinder/images_store/files/runodaminobutatotewirul.pdfIn PDF document text
    • https://webhostmurah.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a9b69c362e0---44663440118.pdfIn PDF document text
    • http://104.156.58.56/~web2inbox/wp-content/plugins/formcraft/file-upload/server/content/files/160a3a3536c310---12112482059.pdfPDF link annotation
    • http://andreevmag.com/wp-content/plugins/super-forms/uploads/php/files/0a74179c3b1ab1bdc7b030c333ef53cc/vukimuloja.pdfIn PDF document text
    • http://www.investing-in-women.com/wp-content/plugins/formcraft/file-upload/server/content/files/160877070047c2---tinogudezexuzuk.pdfIn PDF document text
    • https://intervalhousehamilton.org/ckfinder/userfiles/files/47200843870.pdfIn PDF document text
    • http://www.cascinasorigherio.it/wp-content/plugins/formcraft/file-upload/server/content/files/160bf195db6b7b---51261607273.pdfIn PDF document text
    • https://www.kiteschule-kiel.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609f73813e1bb---kililipizalenu.pdfIn PDF document text
    • http://xycrusher.com/d/files/zuxibotumawejeromozibul.pdfIn PDF document text
    • https://riolospettacoli.it/filesUploads/file/40276460830.pdfIn PDF document text
    • http://vietnam-intraco.com/webroot/img/files/34844282025.pdfIn PDF document text
    • http://tanphatinst.com/vietkiendo/upload/file/nexatavukesewuzanobi.pdfIn PDF document text
    • http://www.neslihanonur.com/wp-content/plugins/super-forms/uploads/php/files/bec26a4df56516241818736926d5fa60/savitopavedixuvixam.pdfIn PDF document text
    • https://unibel.pl/pliki/upload/file/96914179435.pdfIn PDF document text
    • http://skupka23.ru/upload/m/10804867966.pdfIn PDF document text
    • https://brokenspoke.com/wp-content/plugins/super-forms/uploads/php/files/62148a82edfe4a9a8d42eb355b8318ee/xomeliledofasipasiw.pdfIn PDF document text
    • http://driver-jazda.pl/upload/file/14000986061.pdfIn PDF document text
    • https://useoneconvo.com/wp-content/plugins/super-forms/uploads/php/files/341f599bf757634a229aa3a5e41ef3c3/44228289233.pdfIn PDF document text
    • http://studiotecnicobonoli.com/userfiles/files/pimulazimetibe.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/S30rS-6n6vg/uplcv?utm_term=ios+10+beta+software+profile+indirPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb80.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB80 10840 bytes
SHA-256: cd868134611720ebf048c5567db8e02b17e589262364a20097fac75a5788777f
font_01_sfnt_off0001047d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1047D 17580 bytes
SHA-256: 0777757347517835ac624d20e72688bba6109cf8a8f2bff8a5dba8bec7389d69
font_02_sfnt_off0001328c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1328C 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1