Malicious PDF — malware analysis report

Static analysis result for SHA-256 60041ff10f4e44a4…

MALICIOUS

PDF

71.8 KB Created: 2021-09-03 15:27:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-07
MD5: 73cd6ce566edff514ce821ceaaa10a3e SHA-1: 83de54c276d9936980cb10b89b70c0bcc7cd1b23 SHA-256: 60041ff10f4e44a4118151cede920a584b778fc0e7d967e27890373121683bf0
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by ClamAV and an ML classifier. It contains numerous links to compromised WordPress sites and disposable hosting, suggesting a phishing or malware distribution campaign. The embedded URLs, such as 'https://coretry.ru/uplcv?utm_term=scrambled+sentences+present+simple+pdf', are likely used to redirect users to malicious content. No scripts were extracted, but the overall structure and URL patterns indicate a malicious intent to lure users to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9965

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://coretry.ru/uplcv?utm_term=scrambled+sentences+present+simple+pdf PDF link annotation
    • https://spencershaulageltd.co.uk/wp-content/plugins/super-forms/uploads/php/files/76e3930c923df07c7d6b3997d12d679e/jazasotoguzonuteza.pdfIn PDF document text
    • https://purpleleafestatebuyers.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a22d18a97ad---63107110510.pdfIn PDF document text
    • https://x-leather.com/radsportfiles/file/62143070984.pdfIn PDF document text
    • http://www.onegelha.com/wp-content/plugins/super-forms/uploads/php/files/a0f548545b887a77fd65ff769c5f020b/xakafuwonirun.pdfIn PDF document text
    • https://burgas-remonti.com/userfiles/file/lagelosidimumuxomideniz.pdfIn PDF document text
    • https://claphamjunction.com.au/wp-content/plugins/super-forms/uploads/php/files/4b89f0f299e495de70c22490b58942c6/faladogilitovalolasude.pdfIn PDF document text
    • https://deedpoll.sg/wp-content/plugins/super-forms/uploads/php/files/168ccd6901afcc4634c08ab9b96e2883/zipazivojena.pdfIn PDF document text
    • https://qualitycountscleaning.com/wp-content/plugins/super-forms/uploads/php/files/1e90854884d4b6df717280b3e8030a63/94869050676.pdfIn PDF document text
    • http://brighterhealthcare.co.uk/wp-content/plugins/super-forms/uploads/php/files/1h7q5jkh02kupm41a51i1pvmmi/tazijikemekewevevajeriw.pdfIn PDF document text
    • http://sinners-party.de/media/file/78172127527.pdfIn PDF document text
    • http://baobiachau.com/luutru/files/3933386909.pdfIn PDF document text
    • http://www.argentum.com/wp-content/plugins/super-forms/uploads/php/files/7d4e5uhdhcot95gdrivaqvtdk5/begidezalerir.pdfIn PDF document text
    • https://securitydm.rs/slicice/file/79050403253.pdfIn PDF document text
    • http://cuatudongnhatrang.com/uploads/files/jodefi.pdfIn PDF document text
    • http://www.alex-vasilkov.ru/images/wisdom/file/dugububupezepilopezem.pdfIn PDF document text
    • https://swimproject.eu/wp-content/plugins/super-forms/uploads/php/files/c1d986f620f5380cdb1a03e84dcfce74/44374095669.pdfIn PDF document text
    • http://shinserviceodi.ru/wp-content/plugins/super-forms/uploads/php/files/1691b3a7f0877758f91f2fa93afb198d/kozafinomofezisoriguwepe.pdfIn PDF document text
    • https://phnews.ro/files/file/21084070780.pdfIn PDF document text
    • https://pinotcar.com/wp-content/plugins/super-forms/uploads/php/files/d929af06b944c498ed3326c439d15248/18037474858.pdfIn PDF document text
    • https://razdolle.by/wp-content/plugins/super-forms/uploads/php/files/7vnatl383c1b92khm5p35klm94/32578924658.pdfIn PDF document text
    • http://karat-dobremiasto.pl/userfiles/file/40120126902.pdfIn PDF document text
    • http://compsult.net/userfiles/file/99430770283.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b6c8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB6C8 10876 bytes
SHA-256: 2475ccbe7149f3cbe20f4afb5bd8672ac37529602104bb089bf16cd5bb98d208
font_01_sfnt_off0000cf9e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCF9E 16272 bytes
SHA-256: a6f3890757032c6bd13e7df994d926024f32ce96f955033675f78a35882f7a7a
font_02_sfnt_off0000f971.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF971 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1