Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c782903a4a9f2e4…

MALICIOUS

PDF

70.6 KB Created: 2021-04-27 18:54:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 70f389118e738caeaa90055b5ccff0f0 SHA-1: dcdc645e98fa1277b253df0670541d3c83df2542 SHA-256: 5c782903a4a9f2e4a14a2a704d0991fd1aa6320444f3620c1dd752252b54727d
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm pointing to multiple compromised websites, indicating an attempt to host malicious content. ClamAV detected this file as 'Pdf.Phishing.Trojan', and ML classifiers also flagged it as malicious. The presence of external URIs and a high ML score suggest a phishing or trojan delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hk-dcc.com/wp-content/plugins/super-forms/uploads/php/files/ujptqj7j9p8jtq7tu3umuj4p01/vopubuwunefa.pdf
    • https://dermo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a1b1e26c46---32424970663.pdf
    • http://www.orhancoskun.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070ab3c557fb---ninivudesok.pdf
    • https://mebelpozakazu.ru/wp-content/plugins/super-forms/uploads/php/files/b37b6d6ad618b2e30133e078762f1de0/sesagaxum.pdf
    • http://www.dj-csnl.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16071a50e54682---11828477974.pdf
    • https://lasvegasrebath.com/wp-content/plugins/super-forms/uploads/php/files/5e02f4417cd6254a41858a452645c3fa/64994729851.pdf
    • https://www.ccps.mx/wp-content/plugins/super-forms/uploads/php/files/62fbdb82868cf69b6565fdc49517e725/22637597860.pdf
    • https://winston-woodward.com/wp-content/plugins/super-forms/uploads/php/files/3a9fd2cc8b1ae6cf70015f678ead1448/45877618552.pdf
    • https://fellowpeo.com/wp-content/plugins/super-forms/uploads/php/files/d979617ec300e1b35387a7837376580b/1771783943.pdf
    • https://www.parkgest.ch/wp-content/plugins/formcraft/file-upload/server/content/files/1607ff69d16f0d---36864247859.pdf
    • http://www.lauricedale.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/16083870a71a0c---37960675753.pdf
    • https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160850d5e2d6f3---pukefaju.pdf
    • https://www.dishdivvy.com/wp-content/plugins/super-forms/uploads/php/files/a219a97c5a3f2c6f620b2dc549b63f0a/53052150929.pdf
    • https://livingcircles.ch/wp-content/plugins/formcraft/file-upload/server/content/files/16084b899b09cc---mizuromot.pdf
    • http://vegasoft.hr/wp-content/plugins/formcraft/file-upload/server/content/files/1607d7627bd1ea---63785306737.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/skout/mBVl/~3/DOqCt-cVA4I/uplcv?utm_term=apache+kafka+1.+0+cookbook+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d743.bin
0fbb86faa261b987bda05d3e4818df7520da144bb4fe44e5890210a7798809cf
pdf-font-stream PDF embedded font (sfnt) at offset 0xD743 5356 bytes
font_01_sfnt_off0000e984.bin
f1dec5d658ffa9f39b8dc976cad4b9408d7373afc4d51461479a28f20ff1ae6d
pdf-font-stream PDF embedded font (sfnt) at offset 0xE984 10476 bytes