Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ad4174d4685b19c…

MALICIOUS

PDF

79.8 KB Created: 2021-07-04 23:26:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 33224950c235e38eb83fde22dad367bb SHA-1: fa0be76e41bce313781d7bcc03b6f1af84f3b3ef SHA-256: 3ad4174d4685b19c14d956f166d0e266e78b6a154d59bf41d21dc0a256ec5c51
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of links, many of which point to compromised WordPress sites. The ClamAV detection as 'Pdf.Phishing.Trojan' strongly suggests a malicious intent, likely to lure users to phishing pages or download further malware. The file's structure as a link farm on disposable hosting further supports this assessment.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4816

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://awlights.com/wp-content/plugins/super-forms/uploads/php/files/f9641cb3261a76ecd04476b762e5faaa/gogixobejon.pdf
    • http://witnesstherealist.com/wp-content/plugins/super-forms/uploads/php/files/ca571b6b13ee47c25cf5fe4a7f8a2ec3/vuwivikakenidotuxefamokur.pdf
    • http://thegioituigiay.net/uploads/files/48522234604.pdf
    • http://gandolfiarchitetti.com/userfiles/files/18225721239.pdf
    • https://ballestermultiservicios.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607794891e71e---sikogezo.pdf
    • https://www.alphaveneers.com/wp-content/plugins/super-forms/uploads/php/files/5c3a3b27659521018fbb3e45b0b9015e/mimegupovimulopavikupi.pdf
    • http://www.onegelha.com/wp-content/plugins/super-forms/uploads/php/files/3f2e61060977502370a831891342359f/xorinevodubonat.pdf
    • http://www.zopfitravel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160be40816cdd3---47570828915.pdf
    • https://akarchlight.com/wp-content/plugins/super-forms/uploads/php/files/84f4d2ba7bcae388b621184051a0186d/giroxuvokiletukukilojo.pdf
    • http://oaklandscreche.ie/userfiles/files/fasivudi.pdf
    • http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160aae4a12f491---86213492828.pdf
    • http://jnafarms.com/clients/864068/File/xexonetipato.pdf
    • http://www.allatpatikapecs.hu/images/file/77357011507.pdf
    • http://arcdesantmarti.com/biocop/Images/images-editor/file/tevinibodabedajepoboxiraw.pdf
    • https://impresa-valli.it/file/48621892151.pdf
    • https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609451f5ce648---12130171324.pdf
    • http://www.radioemka.com/wp-content/plugins/formcraft/file-upload/server/content/files/160957a2a04e74---2852653359.pdf
    • http://china-engine.net/ckfinder/userfiles/files/vavitawigakorifepunewixew.pdf
    • http://eksan-ltd.com/userfiles/file/26312353327.pdf
    • https://aedwea.com/upload/foto/71467082699.pdf
    • http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160755492bd188---24121435625.pdf
    • http://clarkstownhs64.com/clients/2/25/255c49a504cbad61718694d8b78dfcdd/File/16900953620.pdf
    • http://dangkyidol.com/wp-content/plugins/super-forms/uploads/php/files/r0o7gjdejm6b3rkih626mqifvn/bifegikezuvonev.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/PmAiG5ZyT-k/uplcv?utm_term=12th+math+objective+questions+and+answers+pdf
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e081.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE081 16792 bytes
font_01_sfnt_off0000f898.bin
569443c8fcd0d9e6703cc60d6318e91ae7e4a5bc969cbe7f6887e364c20319c3
pdf-font-stream PDF embedded font (sfnt) at offset 0xF898 11584 bytes
font_02_sfnt_off0001139d.bin
95731807fac5148e96ac1b5562e14ad4220eff1fd674effdac165106f06b9f05
pdf-font-stream PDF embedded font (sfnt) at offset 0x1139D 19024 bytes