Malicious PDF — malware analysis report

Static analysis result for SHA-256 469551c67e8f5fd5…

MALICIOUS

PDF

82.4 KB Created: 2021-09-02 06:52:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-14
MD5: 9b47becccb5d48e4d1095c87addf40eb SHA-1: fb0434d183d9b8cb0ff5deb574e37b60a0c0eda1 SHA-256: 469551c67e8f5fd5770a6c42b7b7fe9cb651a99fd3d31dfc0b4bb3a04b720edd
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It functions as a link farm, containing numerous URLs pointing to compromised WordPress sites and other domains, likely intended to lure users into downloading further malicious content or submitting sensitive information. The presence of multiple links on potentially compromised infrastructure suggests a broad distribution effort.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9978

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://camonetinternational.com/files/file/73245554593.pdf In PDF document text
    • https://agribusiness.pk/wp-content/plugins/formcraft/file-upload/server/content/files/160a0608c27354---10241912922.pdfIn PDF document text
    • http://bascobrunswick.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16074cfd3b0038---libiwelanugefabanow.pdfIn PDF document text
    • https://rimsball.com/ckfinder/userfiles/files/zimafojegu.pdfIn PDF document text
    • https://yodishit.com/uploads/userfiles/file/wemomogu.pdfIn PDF document text
    • http://mdknoodles.co/uploads/files/pumivewotexekegidaleje.pdfIn PDF document text
    • https://pelletier-tp.fr/ckfinder/userfiles/files/jizevowevixuxafuxuxiz.pdfIn PDF document text
    • http://eske.hu/wp-content/plugins/formcraft/file-upload/server/content/files/160842b2b86b9e---kobitedopimewagujowonewet.pdfIn PDF document text
    • https://gpuhub.net/wp-content/plugins/super-forms/uploads/php/files/vtb35t3app84aadadffsped9ra/9277741115.pdfIn PDF document text
    • http://www.holzbau-hoelzl.at/wp-content/plugins/formcraft/file-upload/server/content/files/1608de4c7a605e---87043886739.pdfIn PDF document text
    • http://plkorea77.com/ckupload/files/63700049180.pdfIn PDF document text
    • https://dfa-finanz.de/wp-content/plugins/formcraft/file-upload/server/content/files/160bf284f56b83---notawubivepufur.pdfIn PDF document text
    • http://argentum.com/wp-content/plugins/super-forms/uploads/php/files/5oio9fgkrqenf6lhn3ln0rftbl/10763094915.pdfIn PDF document text
    • https://tosto.cl/ckfinder/userfiles/files/vazulefepitalifijune.pdfIn PDF document text
    • https://baptistfriends.org/media/sopowalitewufesokak.pdfIn PDF document text
    • http://kalikraft.com/images/file/52028891344.pdfIn PDF document text
    • http://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607849b79ba2a---toposifeberixulak.pdfIn PDF document text
    • http://tuanlongland.com/upload/files/80214710455.pdfIn PDF document text
    • https://www.stjohnhomelessshelter.org/wp-content/plugins/super-forms/uploads/php/files/cddbaaf2cd34d0fc65f165bfa8e5023c/gelabesigusazejevo.pdfIn PDF document text
    • http://xn--pr3b03lcdvwu9dpynqkc.com/DATA/file/20210718145144.pdfIn PDF document text
    • https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608127b615f25---nisonosudugizivipexizil.pdfIn PDF document text
    • http://chukgoobok.com/files/fckeditor/file/29293043481.pdfIn PDF document text
    • http://mnogonomerov.ru/uploads/file/50168896329.pdfIn PDF document text
    • https://xn--64-mlcufjjaii0l.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/c20ebc94d7a4e560fd9644865de67e27/jozekamitare.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/LPIa9PGmDLg/uplcv?utm_term=red+spotted+geckoPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dde9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDDE9 17308 bytes
SHA-256: 6fe97ea5d0997d5508a7664a6f00416c7ba3c8df86c54c69b6f3a2c9307775cc
font_01_sfnt_off00010a59.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A59 10324 bytes
SHA-256: 3caea7fde31ca907e545575c6313660ee64a01feff92f2e22bc5f4916276201f
font_02_sfnt_off00012197.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12197 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1