Malicious PDF — malware analysis report

Static analysis result for SHA-256 489ee322deec5697…

MALICIOUS

PDF

125.2 KB Created: 2021-07-17 00:13:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: e1fccadd54bea87f3c5e9bf026f34cfa SHA-1: bb69ae2a5a04dacb871f8ff7f35e386cda7fe97a SHA-256: 489ee322deec5697aa2309122890898f42399d81790e066a8a50bf8edd6f1537
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains a link farm pointing to numerous external URLs, many of which are hosted on compromised WordPress sites. The ML classifier strongly indicated maliciousness, and the structure suggests an attempt to lure users to potentially malicious content or phishing sites. No scripts were extracted, limiting the analysis of direct execution vectors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9910

Heuristics 5

  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://refour.eu/wp-content/plugins/super-forms/uploads/php/files/cd843036b231227fdf95790f5176a3a4/8027704265.pdf
    • https://www.spoton.pet/wp-content/plugins/super-forms/uploads/php/files/t0rbvluat6rcdgrl3okbvimfrf/lurugowenatizavato.pdf
    • https://www.physioaktivkramer.de/wp-content/plugins/formcraft/file-upload/server/content/files/160b3fe6fa8916---48299146634.pdf
    • https://3dreamvr.com/wp-content/plugins/super-forms/uploads/php/files/9693ecc2865683a83bd4aa2eecb2d025/13585644565.pdf
    • https://reifenscho.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608b454752f80---luwutafikonej.pdf
    • https://wurstfargo.com/wp-content/plugins/super-forms/uploads/php/files/3da70411d72d16fd1cf1e1731f421ff4/xatoxosepaxutem.pdf
    • http://grupogmec.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cb793ec2ac7---wiritubi.pdf
    • http://xn--80aafbanafwvcftiqfecrg2a.xn--p1ai/pict/file/72393873751.pdf
    • http://cameronhaddock.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b45b277a9e5---xazokavuworovukivaf.pdf
    • http://www.patricktennis.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160f1f3f713c61---86092460513.pdf
    • https://www.fifatravels.com/wp-content/plugins/formcraft/file-upload/server/content/files/160943632170be---ruvoponilozojodete.pdf
    • http://www.elsecretodelolivo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e372217e42e---32028474168.pdf
    • http://ecohort.com/userfiles/files/tererurukaralafejifiva.pdf
    • http://ximangsongthao.com/app/webroot/uploads/files/vusup.pdf
    • http://cargo3030.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160723ac77c624---gegidewevotavasuvozozejel.pdf
    • https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/c2752ddb5991e4f249dfe9119a2818f6/ninapoxilupitekimex.pdf
    • http://elmiraclassiccountry.com/wp-content/plugins/super-forms/uploads/php/files/invhs55ddippvgla4gdaaojj64/xodubasivajumebagaf.pdf
    • https://www.prestigeautobody.com.au/wp-content/plugins/super-forms/uploads/php/files/7e17bb7e93023a2c95a391869d0c371b/55141179871.pdf
    • https://teenvolunteerdallas.org/wp-content/plugins/super-forms/uploads/php/files/c68b801129ea7734e01254db56410f1e/bapitevivofuguvovevuxa.pdf
    • http://tavaszitura.eu/userfiles/files/69859672797.pdf
    • http://pvsystexperts.com/wp-content/plugins/super-forms/uploads/php/files/3itmkv2261k5n13c0gfli5coi7/lubip.pdf
    • http://handinks.com/ckfinder/images_store/files/fovododadegelojugap.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/S30rS-6n6vg/uplcv?utm_term=nepotism+meaning+in+malayalam
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00017ab7.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x17AB7 16792 bytes
font_01_sfnt_off000192c4.bin
fa092f48aa5904d12d06186b40bc875c89220bb830142058f99d47012a43d50d
pdf-font-stream PDF embedded font (sfnt) at offset 0x192C4 1792 bytes
font_02_sfnt_off00019b35.bin
83dd7f86c3f2fe9e9a032d16d003414286479db5a8b943a020453b4cd160123b
pdf-font-stream PDF embedded font (sfnt) at offset 0x19B35 20868 bytes
font_03_sfnt_off0001ced6.bin
c574769d56706a31125ac282e95193f4a0fffc3848e221e6136f220721fdc658
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CED6 10584 bytes