Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b67d833dc0e2e97…

MALICIOUS

PDF

86.0 KB Created: 2021-07-29 21:47:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 29353fb16e641604d4326443cdcff060 SHA-1: ce09fb4fedd4c3b2ba69f8e2b19788b07a4b59c7 SHA-256: 5b67d833dc0e2e97904248436873cd2ea14814ae8c2c13b386f2a5a392843511
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains embedded JavaScript and numerous external URIs, many of which point to compromised WordPress sites or disposable hosting, suggesting a link farm designed to redirect users to malicious content. The presence of embedded JavaScript indicates an attempt to execute code within the PDF viewer.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9984

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://csc0512.com/userfiles/file/20210726022126_h6w3eo.pdf
    • http://gianphoiduyloimodel.com/Images_upload/files/pepajekovumudalapadup.pdf
    • https://www.grecosalesinternational.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607127f7d4245---vebuvarepukasugoroj.pdf
    • http://reelproductionshd.com/userfiles/file/75527340685.pdf
    • https://earthchartercities.org/wp-content/plugins/formcraft/file-upload/server/content/files/160b3c716a512a---8025532719.pdf
    • http://www.olympussverige.se/wp-content/plugins/super-forms/uploads/php/files/q909es6sftv5sppvett9ek36eq/67225862002.pdf
    • http://musiconthebay.org/clients/2/26/269dd5bc96e197da989a8dccc71442af/File/vuligajasatofux.pdf
    • http://www.a-fairys-choice.com/wp-content/plugins/formcraft/file-upload/server/content/files/16081045f44ce4---kukumoketotawokoxenose.pdf
    • http://jagatjyotischool.org/jagatjyotischool/userfiles/file/74929521031.pdf
    • http://lso-msm.fr/userfiles/file/vozusezutobumato.pdf
    • https://sketchup360.vn/wp-content/plugins/super-forms/uploads/php/files/d1d5ushv0oj32hslp4rsj1msce/fawoxiwewofetadubirawel.pdf
    • http://autoscuolauniversale.it/userfiles/files/jevikitelerifekumopowozid.pdf
    • http://mas.vacations/wp-content/plugins/formcraft/file-upload/server/content/files/1608fb4cbeceaa---fupurubepefeke.pdf
    • http://cameronhaddock.com/wp-content/plugins/formcraft/file-upload/server/content/files/160dd98dc5827d---50701403677.pdf
    • http://jyotiacademicpress.org/uploads/file/84916389061.pdf
    • http://autosvanbeek.nl/mindcms/js/ckf/userfiles/files/dinovug.pdf
    • http://vector-luczak.pl/new/fck_user_files/file/75118393208.pdf
    • https://indiantalentjunction.com/milan/media/8157855863.pdf
    • https://smoothnomad.com/wp-content/plugins/super-forms/uploads/php/files/3vd3q8u5jbl0lppvi7ra4vjive/rojiruxopibijila.pdf
    • http://ccsl.asia/files/69540800584.pdf
    • https://seataclightingalaska.com/wp-content/plugins/super-forms/uploads/php/files/f8e2433efb18e45ddc9c25014fe80839/zasefopotur.pdf
    • http://kaplanpm.com/wp-content/plugins/formcraft/file-upload/server/content/files/160904d9ac9729---ravoselirepodibufidoketip.pdf
    • http://cetinelektrik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160e21746a700a---todufenopajid.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/cv9VXjIrmdE/uplcv?utm_term=addition+word+problems+4th+grade+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb70.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB70 16792 bytes
font_01_sfnt_off00010387.bin
ba5ec91df7e771372d632b0a938d7f49c7f49a8bc9a9f539e87c8e5d9f7d756c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10387 11228 bytes
font_02_sfnt_off00011d4d.bin
d2a9c6eeb8f31a7f3a7ed3f4253290b97eecdbccaecf943f656682c8a1fe0691
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D4D 16976 bytes