Malicious PDF — malware analysis report

Static analysis result for SHA-256 67464c044ae90806…

MALICIOUS

PDF

90.9 KB Created: 2021-06-26 14:53:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-09-13
MD5: afcdb65f3407463c8e80cbfe16dfe6fb SHA-1: b6c08c34c80831dcee04f622129bc2b1060e2c0b SHA-256: 67464c044ae90806d18c39b15bb2e53179926fbca1449fa9d8d47d258beb6d32
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains multiple links to external websites, many of which are hosted on compromised WordPress installations or disposable domains, indicating a phishing or malware distribution attempt. The ClamAV detection and ML classifier strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded links are indicative of a common tactic to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9822

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xn--80akij1ajew.xn--p1ai/wp-content/plugins/formcraft/file-upload/server/content/files/1607d1ff21a1cb---fipufefuwifesoladabejitan.pdf In PDF document text
    • http://www.sg-callenberg.de/wp-content/plugins/formcraft/file-upload/server/content/files/1606d536b8406d---luzulejurufetixedofigadi.pdfIn PDF document text
    • https://abofahed.com/userfiles/file/suresipixobuka.pdfIn PDF document text
    • http://www.thediethub.in/wp-content/plugins/formcraft/file-upload/server/content/files/160a014dc54083---mikaxadokala.pdfIn PDF document text
    • https://www.chartsunlimited.com.ph/wp-content/plugins/formcraft/file-upload/server/content/files/1607a79817027d---82626101598.pdfIn PDF document text
    • https://jiptv.nl/wp-content/plugins/super-forms/uploads/php/files/6bkslmee8dknmh923blop0koth/73332832414.pdfIn PDF document text
    • http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/k1581f9cmghbt3u8bv7un3v3n4/gumizometuvovepewaje.pdfIn PDF document text
    • http://xn--e1aaafipco3bk8gra3b.xn--p1ai/upload_picture/file/sofekuxinamolikidubupudaw.pdfIn PDF document text
    • https://shinyjewellers.com/wp-content/plugins/super-forms/uploads/php/files/ft5kterdo5drd1m3un6rq8cl4q/43567820739.pdfIn PDF document text
    • https://www.indee-r.fr/wp-content/plugins/super-forms/uploads/php/files/3dcb470c600e87ddaa6a182f5029f7f2/xolefaduwe.pdfIn PDF document text
    • https://mosoptagro.ru/wp-content/plugins/super-forms/uploads/php/files/6dff0429828f20fea4a8ffb4a546c60e/fobivozijen.pdfIn PDF document text
    • http://www.jobsincrete.gr/images/_user_na/file/sudugosavirosuxovepisi.pdfIn PDF document text
    • https://www.siemers-deutschmann.de/wp-content/plugins/super-forms/uploads/php/files/pv64a5eji7ep07s6bceu2o8hhb/46048886111.pdfIn PDF document text
    • https://www.ideaklinik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160a8bc09083c5---xavurudar.pdfIn PDF document text
    • http://banhangcongnghe.com/upload/FCK/file/45837564938.pdfIn PDF document text
    • https://www.karavanlakesfet.com/wp-content/plugins/super-forms/uploads/php/files/0bdae58ea078369a3630ea5ab005a1a7/jowivodewomefajul.pdfIn PDF document text
    • http://iziusb.com/userfiles//file/84473745486.pdfIn PDF document text
    • http://thuephotocopytaihanoi.com/upload/files/73004134085.pdfIn PDF document text
    • https://hotelristorantenovecento.it/wp-content/plugins/super-forms/uploads/php/files/e9f678b71f9ecd5f8c8bdc13b823d8c9/renogafominibafimu.pdfIn PDF document text
    • https://biblioteka-koneck.pl/ckfinder/userfiles/files/13137645281.pdfIn PDF document text
    • https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160a4b50fc75f2---bedaruduvu.pdfIn PDF document text
    • https://www.lumisolar.pe/wp-content/plugins/formcraft/file-upload/server/content/files/16098be87de2b7---27844994966.pdfIn PDF document text
    • https://cwlighting.com/wp-content/plugins/super-forms/uploads/php/files/811e6b43a17b52f8e557cf2797b7a027/5232517475.pdfIn PDF document text
    • https://hps-gruppe.com/wp-content/plugins/super-forms/uploads/php/files/u20jd0egmc7pb2miqp8kp980g0/48409699352.pdfIn PDF document text
    • http://jagatjyotischool.org/jagatjyotischool/userfiles/file/13673296315.pdfIn PDF document text
    • http://adhdadvisory.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f8e7ba1325---64536690480.pdfIn PDF document text
    • http://sport-way.ru/img/file/82944779049.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=what+is+a+clinical+therapistPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000101a0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x101A0 10344 bytes
SHA-256: bddd73ab502704793d5e7a383d936934b65eff1c0d394db9c545ffe118a95522
font_01_sfnt_off000118e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x118E6 17684 bytes
SHA-256: 69974eb69a1788f199e32647bed364c7e29e9be17c1a4d8739eb4bed436bd246
font_02_sfnt_off00014621.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14621 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1