Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e061e5f021df7d1…

MALICIOUS

PDF

88.7 KB Created: 2021-08-17 15:30:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-11
MD5: aed226bf93fbef91fe806e8353e2c8de SHA-1: de409d32dddb8fc61b555978f733cfb8424b65c8 SHA-256: 4e061e5f021df7d1dddfddcc465d9b5a4f371c8c247674c3eee2fe964c01c6a0
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded URLs, many of which point to compromised websites or disposable hosting, indicative of a link farm. Heuristics like 'PDF_SEO_DISPOSABLE_LINK_FARM' and 'PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM' strongly suggest this malicious intent. The ClamAV detection as 'Pdf.Phishing.Trojan' further supports the malicious classification, likely due to the deceptive nature of the linked content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8446

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vandervalk.reviews/app/webroot/files/userfiles/files/82910588927.pdf In PDF document text
    • https://eltonltd.ru/sites/default/files/uploads/gitesuwiwapukuke.pdfIn PDF document text
    • http://antik-cafe-bergen.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609ef4e63da3e---zitogowapinigunar.pdfIn PDF document text
    • http://www.trackls.com/application/ckeditor/ckfinder/userfiles/files/domevedusafenopo.pdfIn PDF document text
    • https://uaqbakery.com/wp-content/plugins/formcraft/file-upload/server/content/files/160beee131d885---xasibe.pdfIn PDF document text
    • https://apoiotelecom.com/imagens/img_fckeditor/file/rerezuradavotokev.pdfIn PDF document text
    • https://www.dekleinewerf.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160813daa87918---miroginurefakipamix.pdfIn PDF document text
    • http://toyotacri.com/userfiles/files/kaforinezasuw.pdfIn PDF document text
    • https://totalyoumovement.com/wp-content/plugins/formcraft/file-upload/server/content/files/160dee24db98ff---50583299249.pdfIn PDF document text
    • https://digidatadecolombia.com/wp-content/plugins/super-forms/uploads/php/files/36b797c11860e8a4a868faabafef349f/burerimexigejavugate.pdfIn PDF document text
    • https://elitestrategyglobal.com/wp-content/plugins/super-forms/uploads/php/files/b41e5052b5c6402d048b626a0555f72d/88645960223.pdfIn PDF document text
    • https://beaufortbond.com/wp-content/plugins/super-forms/uploads/php/files/86d5fa763297841c1c433bb250fcfff8/43131395407.pdfIn PDF document text
    • http://norilskgu.ru/userfiles/file/talux.pdfIn PDF document text
    • http://nordicaluminium.ru/userfiles/file/71879623076.pdfIn PDF document text
    • https://www.alertgy.com/wp-content/plugins/super-forms/uploads/php/files/76a02f5a3e8bd996ceeb3e851f67c6e8/43333724894.pdfIn PDF document text
    • https://mmagame.com/userfiles/file/bosefarazumiro.pdfIn PDF document text
    • http://www.melloecastro.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608b373c22982---77312224481.pdfIn PDF document text
    • http://whscardinals1963.com/clients/9/9e/9e5fab02d16e7113a74bdd4e7828f974/File/wubinufuwu.pdfIn PDF document text
    • https://konzolstudio.ro/uploaded_files/file/95794552310.pdfIn PDF document text
    • http://beetsom.com/PROGRAM_FCKeditor_UserFiles/file/212238128260a6d4d737c53.pdfIn PDF document text
    • https://fainitelecommunication.com/public/editorfiles/file/65815064280.pdfIn PDF document text
    • https://www.analfissur.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607d45f298055---norovizifuleremopurokabet.pdfIn PDF document text
    • http://huichem.com/ckfinder/userfiles/files/nurowi.pdfIn PDF document text
    • http://sushibelovo.ru/files/93741707015.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/1KS0DP0cxss/uplcv?utm_term=structural+engineering+formulas+pdfPDF link annotation
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000103a5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x103A5 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off00011bbc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11BBC 11136 bytes
SHA-256: 814ff39c06a9d7ba67f235889aa4e5b97ce1b9d3e9384e65919fa2929aaae7cf
font_02_sfnt_off00013582.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13582 19244 bytes
SHA-256: 8c41e54c17e1eaeb1e0747a85caf1934697a080718a060c1e46fe112320c2493