Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f7fb1596878b7fa…

MALICIOUS

PDF

117.9 KB Created: 2021-07-29 18:59:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-07
MD5: 08082c6e3f771ae447a097137f4df3da SHA-1: 52019e84db564d9c7c0381cb0b5d05ad58751de1 SHA-256: 3f7fb1596878b7fa78cbc75b294967bf66e96fd3d5244282dd164bd1b7ac36b7
132 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded JavaScript and a significant number of external links, many pointing to compromised websites or disposable hosting, indicative of a link farm. The ClamAV detection as 'Pdf.Phishing.Trojan' strongly suggests a malicious intent, likely to lure users to phishing sites or download further malware. The embedded JavaScript is likely used to facilitate the redirection or obfuscate the malicious links.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4014

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ketchas.ru/uplcv?utm_term=the+legend+of+zelda+ocarina+of+time+master+quest+differences PDF link annotation
    • https://biocoils.com/img/file/kunare.pdfIn PDF document text
    • https://www.endthestigmacounselling.com/wp-content/plugins/super-forms/uploads/php/files/5fvpb1nj9h8fjg3soc6m9iq6ka/26449675578.pdfIn PDF document text
    • http://eventologia.com/userfiles/files/56365049262.pdfIn PDF document text
    • http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/8rgru8qaemeulpphq2n5d66kf5/26981815446.pdfIn PDF document text
    • https://gaseg.com/wp-content/plugins/super-forms/uploads/php/files/ifp1e6paf8k1d4sv3tevahaqqt/zotenapawoxasetigopik.pdfIn PDF document text
    • http://kennyre.com/wp-content/plugins/formcraft/file-upload/server/content/files/1610118558941b---kulejiw.pdfIn PDF document text
    • http://redsky.tv/userfiles/files/fitifuxevumaporakep.pdfIn PDF document text
    • http://itaindustrial.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609b08f364362---levudejuv.pdfIn PDF document text
    • https://action-roofing.com/wp-content/plugins/super-forms/uploads/php/files/d508541d87afd5fcb03825cb3f6572fa/binomemixiwolevufo.pdfIn PDF document text
    • http://andreagarciam.com/wp-content/plugins/formcraft/file-upload/server/content/files/160713c07f16d2---11877017347.pdfIn PDF document text
    • https://cremeconferences.com/wp-content/plugins/super-forms/uploads/php/files/26732e0555bb4bc999dc5cd721e8e217/vusinosuwifitarenafek.pdfIn PDF document text
    • http://ciccioinpentola.com/userfiles/files/47946608101.pdfIn PDF document text
    • http://www.gainerwindows.ca/wp-content/plugins/super-forms/uploads/php/files/8ceuqoo10no8nnmlphvj46fbl6/63498861456.pdfIn PDF document text
    • https://chocoinmobiliario.com/wp-content/plugins/super-forms/uploads/php/files/38a387b2940648def53d2c5b43580b21/47509854916.pdfIn PDF document text
    • http://czpohledavky.cz/userfiles/files/xavinevutaxo.pdfIn PDF document text
    • http://sk-massimo.com/js/upload/files/55306792755.pdfIn PDF document text
    • https://nowbali.co.id/wp-content/plugins/formcraft/file-upload/server/content/files/16072ea708690f---61901338546.pdfIn PDF document text
    • http://www.sunarozlem.com.tr/wp-content/plugins/super-forms/uploads/php/files/ujmrm5655h11kec2g3ncav0gv5/jimejeloxexeta.pdfIn PDF document text
    • http://dodici12.ru/wp-content/plugins/super-forms/uploads/php/files/u7png6q3oggkrt41ba3ioea9b0/75717366153.pdfIn PDF document text
    • http://xn--e1aaafipco3bk8gra3b.xn--p1ai/upload_picture/file/mumebobaxupimi.pdfIn PDF document text
    • http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609760802e0c4---gaxuxoxabaliki.pdfIn PDF document text
    • http://salonlomi.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160be4347358d7---gugirazolorisanasinazob.pdfIn PDF document text
    • http://www.assignproject.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609762b79878f---wubekukosivunawupesilifid.pdfIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018a23.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18A23 17896 bytes
SHA-256: 113918dd2bb5198945732c8a0e4082bda6449d814396442df7754455d2525048
font_01_sfnt_off0001b8f5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B8F5 11192 bytes
SHA-256: 67c9242e88f8af336c624d1142f475c9ee097ef2e8c15732ddb92f0d5cf82143