Malicious PDF — malware analysis report

Static analysis result for SHA-256 4781f6cb03f1c2b8…

MALICIOUS

PDF

98.8 KB Created: 2021-08-10 03:54:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: b54bf630117d7bb062a8c054137e917c SHA-1: 99108f4d951ec1addc47f1fe4dd845cc0fb43f27 SHA-256: 4781f6cb03f1c2b883ba10256387731a579233525ef2150c6ef85d6e10952f8c
112 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains an embedded JavaScript stream and numerous external URIs, many of which point to compromised WordPress sites and disposable hosting. This suggests the document is designed to act as a link farm, potentially for SEO manipulation or to distribute further malicious content. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious workflow.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 7

  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://oio.cn/uploadfiles/files/46337371789.pdf
    • https://ahreco.com/uploads/news_file/xakirivixoputixijarasixex.pdf
    • https://condominiobrisasdelnorte.com/userfiles/file/29112226794.pdf
    • http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160e4fa458a04f---dakozurez.pdf
    • http://test.uebersetzungen-nesselberger.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607ce22b4c1ad---tuwutesimelawit.pdf
    • https://puertoestereo.com/wp-content/plugins/super-forms/uploads/php/files/vm2fu0816d1e9ttn6cnoo6e6j0/33214877376.pdf
    • http://www.birapart.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c71dc49915e---76150483210.pdf
    • http://whscardinals1963.com/clients/9/9e/9e5fab02d16e7113a74bdd4e7828f974/File/vevew.pdf
    • https://cardion.dk/gfx/fckimages/file/zonitogazitiwos.pdf
    • http://akkoryazilim.com/userfiles/file/nefazodasaz.pdf
    • https://mecaniquekd.ca/upload/file/77076021040.pdf
    • http://denprokhorov.ru/images/file/9271126528.pdf
    • https://impariant-club.ru/wp-content/plugins/super-forms/uploads/php/files/ca4083f47a21366a7a3272f55785f97a/6592449872.pdf
    • https://bruceautoservice.com/files/file/95689503620.pdf
    • https://mldom.xyz/web/img/podborky/files/75496861202.pdf
    • http://www.aaar.cat/assets/js/ckfinder/userfiles/files/54941145563.pdf
    • http://jinruily.com/UploadFile/file/20210726064620701.pdf
    • https://alternativecarrepair.com/userfiles/file/danodudezatovus.pdf
    • http://mrbossamktown.com/uploads/files/16637316887.pdf
    • http://raunlarose.us/wp-content/plugins/formcraft/file-upload/server/content/files/16071dc7b5ac45---tisaniredatipeka.pdf
    • https://www.eziblank.com/wp-content/plugins/super-forms/uploads/php/files/k9fva8ksrv8tg23v49rf3rs3n2/29736986864.pdf
    • http://morgancountyoh.com/userimages/11495240983.pdf
    • http://x-site.by/upload/editor/files/40546308876.pdf
    • http://laclonghotel.vn/upload/files/xezitukimosefegelere.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=glencoe+geometry+chapter+2-1+answers
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000113cc.bin
dc7c38366a37effa2ab8a391d5549fb4c6c3f5e5a031d92db5d0b1aea0923fcb
pdf-font-stream PDF embedded font (sfnt) at offset 0x113CC 11172 bytes
font_01_sfnt_off00012e03.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E03 16792 bytes
font_02_sfnt_off00014615.bin
03cf70f2f43b2863362bed1fe7c8a8a987fc523c6c7e6ae75cc766748f211792
pdf-font-stream PDF embedded font (sfnt) at offset 0x14615 20872 bytes