Malicious PDF — malware analysis report

Static analysis result for SHA-256 5a7a1bd36074a18e…

MALICIOUS

PDF

94.2 KB Created: 2021-07-03 05:00:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 2873b45ffadd802422ba24fc0251cbb1 SHA-1: db8cb9a5c0895984f374bc47504d6cf7c0635ec3 SHA-256: 5a7a1bd36074a18e6ceb9bf28c80e47238227a6a6b3f7543c02d2a5e47d102f2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous links, many of which point to compromised WordPress sites or disposable hosting, indicating a link farm designed to redirect users to potentially malicious content. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware delivery through these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9820

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bpsstudio.hu/uploads/karukupuv.pdf
    • http://timatey.kz/wp-content/plugins/super-forms/uploads/php/files/totl2ssdcoq9cqb58193eeash0/duzafogiwazekopawawiruzaw.pdf
    • https://sgpropertylawyers.com/wp-content/plugins/super-forms/uploads/php/files/c2ecf559bb52dd8b45b0b8c1a592b8e8/latuvazu.pdf
    • https://vietfun.com.vn/wp-content/plugins/super-forms/uploads/php/files/pqnavdri7546smsmehu8coit8q/78810319902.pdf
    • https://napraforgohotel.hu/upload/file/8092254663.pdf
    • http://adaviestransportltd.com/userfiles/file/18479511407.pdf
    • https://samowar.ch/upload/file/1964475011.pdf
    • https://www.ferienhof-schneider.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609a7bec393e6---daxelafajebesibixefa.pdf
    • https://stefandes.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086a0bca3d4d---22257261294.pdf
    • http://birzebbugastpetersfc.com/files/file/12970522782.pdf
    • http://www.xpresswedding.com/wp-content/plugins/formcraft/file-upload/server/content/files/160878dae98cd4---4036637890.pdf
    • http://ozdoby-betonowe21.pl/Upload/file/damaxafare.pdf
    • https://triangle-electronics.com/assets/userfiles/file/44680128183.pdf
    • https://hotelristorantenovecento.it/wp-content/plugins/super-forms/uploads/php/files/90447bc423ec677b6719a62ef8bcdd25/wisaluzozom.pdf
    • http://ngpsusa.com/wp-content/plugins/super-forms/uploads/php/files/bd969ak57imup86sdam2vpvk7f/99234389493.pdf
    • https://allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/a251de6ba2afd945707d8b28a6544388/96467875061.pdf
    • http://nousgarage.com/userfiles/file/90535984276.pdf
    • https://velvetskin.pl/wp-content/plugins/super-forms/uploads/php/files/a9dd14490b7cd0343a76675629b26665/29311278576.pdf
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a6d5c191bb6---7336592615.pdf
    • https://floorco.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/3308621fd4db3d9ad9ff012739de17c2/76566631078.pdf
    • https://mandalaconfeccao.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160827be6a5003---27814654089.pdf
    • http://masonfamilyreunion.org/clients/b/bd/bdaf0a3c19eb5f10f0519c747c117e37/File/wowabesexolelenoji.pdf
    • http://www.champcaregivers.com/wp-content/plugins/formcraft/file-upload/server/content/files/160777ec88f551---49252225833.pdf
    • https://aaaxxion.info/images/file/77774702258.pdf
    • https://travolution.travel/wp-content/plugins/super-forms/uploads/php/files/5665169892703d3582f1a8fb084f166d/47343822691.pdf
    • https://noddy.nu/images/file/xapalagomovosoponovusi.pdf
    • https://feedproxy.google.com/~r/skout/mBVl/~3/YTWXjIUwRh0/uplcv?utm_term=quick+answers+to+interview+questions
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010b3b.bin
4ffb81190596ef6209b19bc4b3e7541e908294c5c309a3d6440e7567ae62f8d3
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B3B 17848 bytes
font_01_sfnt_off00013a1f.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x13A1F 16792 bytes
font_02_sfnt_off00015236.bin
a0d7fd7b0532f27a883f3751651a300bf4a06245e4b98942b38371971343fdca
pdf-font-stream PDF embedded font (sfnt) at offset 0x15236 10724 bytes