Malicious PDF — malware analysis report

Static analysis result for SHA-256 4d1b45746b08942f…

MALICIOUS

PDF

85.2 KB Created: 2021-06-26 00:17:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-08-25
MD5: 5a6b96708390d78fec1a78fe0389cd8e SHA-1: 9bdcb60f45adb45e1946ceb4e9148b4ed5eae320 SHA-256: 4d1b45746b08942fc7d8f1b60c9a97cfb921cf0bb50dc29452ecbd33ca999fb1
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains numerous embedded URLs, many of which point to compromised WordPress sites or disposable hosting, indicating a link farm designed to redirect users. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware delivery. The heuristic 'SE_URGENCY_LURE' suggests the document may attempt to create a false sense of urgency to prompt user interaction.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9951

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bluetact.com/locktactyuma/userfiles/file/wugov.pdf In PDF document text
    • http://marcobernini.it/userfiles/files/44221317624.pdfIn PDF document text
    • https://avis-medical.ma/wp-content/plugins/super-forms/uploads/php/files/84704fb668dc9083fdb04baa8f1a53a2/nisalukonuxibus.pdfIn PDF document text
    • http://kamkmori.cz/ckfinder/userfiles/files/leziwe.pdfIn PDF document text
    • https://www.nestroots.com/wp-content/plugins/super-forms/uploads/php/files/if446u2d2ktt7gdoimen40jda1/pokanejojoxinegoxa.pdfIn PDF document text
    • http://www.191seo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160985b3507e9b---bowewo.pdfIn PDF document text
    • http://gd-weimi.com/upfolder/e/files/20210607152311.pdfIn PDF document text
    • http://dragonera.cn/admin/userfiles/file/82785342332.pdfIn PDF document text
    • http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/16097042062247---vanapuporazuzaluzetadalug.pdfIn PDF document text
    • http://www.investing-in-women.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ef772920fd---86363367820.pdfIn PDF document text
    • https://www.hintonassociates.com/wp-content/plugins/super-forms/uploads/php/files/d180c510c5a2d4dfa9c1c5a9a0483d0c/95575889008.pdfIn PDF document text
    • https://www.vibrationmonitoring.asia/wp-content/plugins/formcraft/file-upload/server/content/files/160b2cfcb2962f---38824718464.pdfIn PDF document text
    • https://www.travelticket.com.au/wp-content/plugins/super-forms/uploads/php/files/751rrpdne8mft82su7evck35dq/butevat.pdfIn PDF document text
    • https://fablab808.com/nbloom/fckuploads/file/surozaderikajasef.pdfIn PDF document text
    • https://www.rogierstoel.nl/wp-content/plugins/super-forms/uploads/php/files/aq1iobovfaotf6m5nooultnqc2/xokoxebi.pdfIn PDF document text
    • http://mesotects.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083640d207f8---gigaxamijipupereresejasal.pdfIn PDF document text
    • https://miamivanservice.net/wp-content/plugins/formcraft/file-upload/server/content/files/1609d1d9014263---29718897602.pdfIn PDF document text
    • http://www.hangmandigital.com/files/file/tavekegoso.pdfIn PDF document text
    • http://sh8ke.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608796e74ed6f---pakilegufomezan.pdfIn PDF document text
    • https://socohoteldanang.com/uploads/image/files/fixofupu.pdfIn PDF document text
    • https://chamsocmuihong.com/wp-content/plugins/super-forms/uploads/php/files/rq24fi4u3oe5m9spj0lb6o898j/popukupewawosaxutuzukeme.pdfIn PDF document text
    • https://oddluzanie.net/userfiles/file/73173757647.pdfIn PDF document text
    • https://www.asahinafunnels.com/wp-content/plugins/super-forms/uploads/php/files/agpnr7da44jii5keetqujmehjm/28089028848.pdfIn PDF document text
    • https://adbetelparaguay.com/wp-content/plugins/super-forms/uploads/php/files/452abc44c1bef5304143a3714977b3d2/zixodolefozesivade.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/GLLx1DTH0VQ/uplcv?utm_term=why+i+want+to+hire+you+answerPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e845.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE845 10452 bytes
SHA-256: e63b192acb6761819d84af675f1835e1aa6ab978349dbc93c56659a9812db5d6
font_01_sfnt_off0001000f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1000F 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00011821.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11821 17520 bytes
SHA-256: 5fcda7c821a820d6a29865adc22e6f2f074296635cc2b7dcc447613c53b91d8b