Malicious PDF — malware analysis report

Static analysis result for SHA-256 3bb1d9edb695ad8a…

MALICIOUS

PDF

648.0 KB Created: 2021-07-09 14:55:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: a31a571598b6a89721bff05dbc787d55 SHA-1: 0a319608c6aba390a9de591a1ae1fee3c5abef0d SHA-256: 3bb1d9edb695ad8a2c46cac69e40fd66985607ac743ed74d6f216c50de02f12d
206 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document identified as malicious by ClamAV and an ML classifier. Heuristics indicate it contains links to compromised WordPress sites and lures consistent with an advance-fee scam, likely aiming to trick users into believing they have won a prize or are due a large sum of money. The document's structure and embedded links suggest it is intended to be delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6549

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://d4scanada.com/clients/8/81/81a8d3ecf29e0a7d9042e8364394d873/File/39216881066.pdf
    • https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/abe5243bbd18ac3f01df923de3ad5191/vesapomosakiwenugafuwe.pdf
    • https://ludifrance.fr/userfiles/file/lizaxa.pdf
    • http://e-kva.ru/admin/ckfinder/userfiles/files/pituvanas.pdf
    • https://sweetestspaparty.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d8b00ad3cb---23318367274.pdf
    • https://datatech-int.com/userfiles/file/konobikolufofotaripesog.pdf
    • http://yuseigachi.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160dca661cb187---kojiragogirafo.pdf
    • http://tele-video.ru/upload/files/fazonufometubozalafojagid.pdf
    • https://www.potterycommercials.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160b48394a9146---toloxifejamobelitu.pdf
    • https://www.americanapi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085baaf39f11---kexedigejabez.pdf
    • https://liniagdanskzydowo.pl/files/kolikivigobojirobolu.pdf
    • http://www.orarestauratorisaf.it/wp-content/plugins/formcraft/file-upload/server/content/files/160c002545e59c---37256156734.pdf
    • https://propertiproperty.com/Uploads/userfiles/files/panevenonaxusekuk.pdf
    • http://casinodanmarkjackpot.dk/userfiles/file/450682425.pdf
    • https://youstore21.com/wp-content/plugins/super-forms/uploads/php/files/41a03b8bf23d153a17227294602fdfaa/98690379779.pdf
    • http://sl-light.ru/design/img/upload/file/wusew.pdf
    • https://blueridgelightingandcontrols.com/wp-content/plugins/super-forms/uploads/php/files/f6662825dbdc7c5def19efa47c7efcd9/juvetunidasagikoguv.pdf
    • http://cariboohose.com/userfiles/file/11119810579.pdf
    • http://ajisushionline.com/uploads/files/xawotu.pdf
    • http://aa-nusd.jp/19751823250.pdf
    • http://doublehappyvstheinfinitesadness.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b5c3ff2a530---3874765942.pdf
    • https://rffsev.ru/wp-content/plugins/super-forms/uploads/php/files/908b6d73e7b5c765e462a2096808391e/93616035809.pdf
    • https://zlatartopalovic.rs//files/jogebijudobotawiruwafi.pdf
    • http://amako-ra.com/wp-content/plugins/super-forms/uploads/php/files/6eac7ec172c3fe3514435871b0681d18/tujajebirovoguzulijenelid.pdf
    • http://fontanarosaserigrafia.it/userfiles/file/95963233908.pdf
    • http://bridgestone-ice-cruiser-7000.ru/ckfinder/userfiles/files/40656215354.pdf
    • http://eshop-kocicinadeje.cz/files/file/romagetevapesuzewesosofi.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=fleming+beer+and+food
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0009a99a.bin
057e3eeedf64a9716944ed03a8a0f1de7b909bafa9cf29e716c9cb003e4b317b
pdf-font-stream PDF embedded font (sfnt) at offset 0x9A99A 10548 bytes
font_01_sfnt_off0009c147.bin
823d6d2bf795d8b7a0ec74f655d34e53b617c27af02aa29d9b5faddbe423d8ea
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C147 21116 bytes
font_02_sfnt_off0009f790.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F790 16792 bytes