Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c5af6fb8f21b647…

MALICIOUS

PDF

198.0 KB Created: 2021-07-01 15:51:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 5acc1a03dc5d0d26e275e1a757b1775f SHA-1: d0e16e051e50c3fdb41fac40c69dd7728e7fadb7 SHA-256: 5c5af6fb8f21b6479e41c5862b54ff8e13c38fcca99bd80e8adf59c58869b1ab
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ML classifier and ClamAV detection strongly indicate malicious intent. The PDF contains numerous links, including one pointing to compromised WordPress upload storage, and another external URI, suggesting it's designed to redirect users to phishing or malware hosting sites. While no scripts were explicitly extracted, the PDF structure and link farm heuristics point towards a phishing or credential harvesting attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9092

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://queure.ru/uplcv?utm_term=prayer+for+fast+and+safe+delivery
    • http://www.idenet.net/wp-content/plugins/formcraft/file-upload/server/content/files/160a3de23be251---90457877127.pdf
    • https://ailani.org/wp-content/plugins/super-forms/uploads/php/files/a86e8b3e87220093c4c7a3c11d39e4ad/51523752038.pdf
    • http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160c6f4d402460---samap.pdf
    • https://www.modianodesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608aadf79bc3a---mosepazekepi.pdf
    • https://maxim-catering.de/wp-content/plugins/super-forms/uploads/php/files/7spmosre7ks7dukumpuu1nb2u5/zinul.pdf
    • https://inclinedigital.com/wp-content/plugins/formcraft/file-upload/server/content/files/16092b88d5b329---ganisofukizezuze.pdf
    • http://ekolojikweb.net/upld/userfiles/file/finilexulira.pdf
    • https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/16098f4db11017---vawoxafewinubulolidoga.pdf
    • http://micronforgacsolo.hu/UserFiles/file/nopagawu.pdf
    • http://www.alex-vasilkov.ru/images/wisdom/file/xusuwedofulawumamowedoso.pdf
    • http://wernitznigg.at/files/putexugipa.pdf
    • http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c87ae98ae45---90431379201.pdf
    • https://www.landalastadservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bc9d28a3b6---37805353121.pdf
    • http://tydafa.com/dafa/uploadfiles/20210622134349.pdf
    • https://dfa-finanz.de/wp-content/plugins/formcraft/file-upload/server/content/files/160cfb42b1883d---264975515.pdf
    • http://artside.org/data/temp/file/53941894244.pdf
    • http://www.lbf-cosmetics.com/website/wp-content/plugins/formcraft/file-upload/server/content/files/1609b74cd83861---86585595867.pdf
    • https://123kozijnofferte.nl/wp-content/plugins/super-forms/uploads/php/files/3at118p15vauhk2heekhrg18q3/bamedokesebidilizimupil.pdf
    • https://hissekurban.com/resimler/files/5900535246.pdf
    • http://xn--80ackbssfuieecff0e8c.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/dtpp896n6tifeggqgllg1akce1/53383076412.pdf
    • https://reitinguok.lt/userfiles/file/77514551379.pdf
    • https://xn--80aaaglcftt5alesfkk7f.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/c03634c04852c50e1145794d98118f5b/70344112436.pdf
    • http://dodici12.ru/wp-content/plugins/super-forms/uploads/php/files/f007krj96kb3jojodqgf152b50/81566538078.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0002b389.bin
1d6aaa1ba6e6da44da6f0b3cf7405f0f54c3b08f1b57fc2157c4cbe5d04721ee
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2B389 34772 bytes
font_00_sfnt_off00026d89.bin
e47bf1315cb28e6908e8ff7c5a0b5750bc8c347c9c60f4ce992c2c33309638ae
pdf-font-stream PDF embedded font (sfnt) at offset 0x26D89 17912 bytes
font_01_sfnt_off00029b78.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x29B78 16792 bytes
font_03_sfnt_off0002f1ff.bin
53d0036bec9ff5ec368189ee68e590dd25a81035df27fd925ff41eb4adf7e81a
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F1FF 10528 bytes