Malicious PDF — malware analysis report

Static analysis result for SHA-256 50be8ccd1b57bd81…

MALICIOUS

PDF

221.7 KB Created: 2021-06-26 03:32:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 67ce52205f20ec02be96b6631dc31fc3 SHA-1: e6e80e57874f2abbe1e80d6c93e1417e3aa9b11c SHA-256: 50be8ccd1b57bd81bc0ca41a28db8dfc29fa235a30779d011c512fe940376190
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. The presence of a 'PDF link farm points to compromised-WordPress upload storage' heuristic, along with numerous unknown reputation URLs, strongly suggests a phishing or malware distribution attempt. Although no scripts were explicitly extracted, the PDF structure and URL patterns indicate it's designed to redirect users to malicious content hosted on compromised sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9603

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://sieuviet.net/webroot/img/files/wigakulovamuxuxarifuwex.pdf
    • http://upoart.com/ckfinder/userfiles/files/negage.pdf
    • https://humanistbeauty.com/wp-content/plugins/super-forms/uploads/php/files/fnqvbmhsn21dltah835tlpit63/fuwavipipetizaritomevojas.pdf
    • https://siphouse96.com/wp-content/plugins/super-forms/uploads/php/files/c2380d0fae50041367175208b7aeb967/mulax.pdf
    • http://www.aluvascientific.com/UserFiles/file/23176779288.pdf
    • https://sellerflows.com/wp-content/plugins/super-forms/uploads/php/files/1a41cc7f5a8abca6eede76fd8bcf9047/lolamawolilipat.pdf
    • http://www.sensible-seeds-premium.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a035cef909---labipeg.pdf
    • http://aftckwt.com/uploads/file/lasapa.pdf
    • https://www.hediyevideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071eabcb897e---wetulemumixere.pdf
    • http://fbchitchcock.org/clients/8/8b/8bdff38a390027835eb24981312b950c/File/moweliporobutufamufupit.pdf
    • https://strategieb2b.com/userfiles/file/vilugekonumefigef.pdf
    • https://cspdental.com/wp-content/plugins/super-forms/uploads/php/files/3f619c88a7bfc661b1a2336b7d81c1c6/ditowedunokevor.pdf
    • http://netpost.vn/upload/userfiles/files/21950992967.pdf
    • https://www.azembay.com/wp-content/plugins/super-forms/uploads/php/files/b5c68v22k8bdu76h519b6a0aln/65287010314.pdf
    • https://www.truesdalepainting.com/wp-content/plugins/formcraft/file-upload/server/content/files/160826745f38a7---vegow.pdf
    • https://akarchlight.com/wp-content/plugins/super-forms/uploads/php/files/94b3cc52ce374afe834cd30e3744e0ba/regaz.pdf
    • https://opuntia.eu/wp-content/plugins/super-forms/uploads/php/files/e5906b3a67ff08b78f0f3d47f54ba920/vavapubijoxopigudem.pdf
    • http://perfectthesale.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a1de052c6ab---xikafixutiziremek.pdf
    • http://www.maoles.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609dd97e34595---25002958693.pdf
    • http://partnercable.hu/files/vemadenalajajejobubude.pdf
    • http://thefutureofgolf.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16097c20f1a3e2---kapepanotipom.pdf
    • http://plenaadoracao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160788a457f278---pinotewepujuwuxogeruj.pdf
    • http://dtcguild.org/clients/80367/File/woletekiruzoworonaku.pdf
    • https://www.bakirkoytemsilcisi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607570e24f1ba---35218911991.pdf
    • https://ildiko-szepsegszalon.hu/userfiles/file/pimogi.pdf
    • https://pikewallis.no/wp-content/plugins/formcraft/file-upload/server/content/files/16096ce152fa30---13025479358.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=performing+a+baptism
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002dce4.bin
3f673f44d38080c86e2680c69c739ce659ae7e57ea12bf263d5c226c04a02cc1
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DCE4 10796 bytes
font_01_sfnt_off0002f593.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F593 16792 bytes
font_02_sfnt_off00030da4.bin
f656c6dde543215362a32820ec0dcf9a957a9f0d0039979eb898ddf5c4819086
pdf-font-stream PDF embedded font (sfnt) at offset 0x30DA4 17324 bytes
font_03_sfnt_off000327a6.bin
dc0fffcb32fa604349f0466d98a9f934e2dfdb5e61885671fb83b9d1032b868f
pdf-font-stream PDF embedded font (sfnt) at offset 0x327A6 26404 bytes