Malicious PDF — malware analysis report

Static analysis result for SHA-256 69aeda377185c92e…

MALICIOUS

PDF

132.7 KB Created: 2021-07-26 02:19:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 1a615317e2bc41be0c6c0b4f438fbdd9 SHA-1: 6a80287d34bc53bb52466b6329ccd6694d87db63 SHA-256: 69aeda377185c92e070e67ba71f504a8abaade6d1522b7c9e0fab9ac9dd6742d
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm pointing to various PDF files hosted on disposable domains, a common tactic for distributing malicious payloads. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic indicates the document likely instructs the user to open a password-protected archive, a method used to bypass gateway security. The ML classifier and ClamAV detection strongly suggest malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9907

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ourhkg.com/UPFILE/userfiles/files/webaguleka.pdf
    • http://smepil.com/ckeditor/userfiles/files/32114720922.pdf
    • https://www.cedicar.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085bf49d1462---razazuvifetusenomukik.pdf
    • https://sellerflows.com/wp-content/plugins/super-forms/uploads/php/files/b6143b5cd41618e2277246db6badf5db/titulawurepu.pdf
    • http://mrs724.ir/basefile/drtiketcom/files/nemamo.pdf
    • http://cc-loges.com/uploads/file/34299785592.pdf
    • http://mientaytourist.com/uploads/files/medozumimataremitozatinux.pdf
    • http://udclassof1968.com/clients/74076/File/voligupakinaloj.pdf
    • http://goraku-sangyo.com/userfiles/file/xunizinenafopunup.pdf
    • https://www.heainc.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb9eb463bea---waduruwukenegesuvemivipav.pdf
    • https://pet-fashion.ro/mm/file/18658629516.pdf
    • https://lorenzonimmigrationlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608665298adcf---41267163404.pdf
    • https://aslimitada.com/userfiles/file/95991097711.pdf
    • http://heyumpnd.com/userfiles/file///gugerewesoputirajejexator.pdf
    • https://sunwayhk.com/louis/STARKGROUP/ckfinder/userfiles/files/62544977362.pdf
    • http://obrienbuilders.com/userfiles/file/87894781124.pdf
    • https://fertilizerproductionprocess.com/d/files/tuvuvitutilabul.pdf
    • https://www.mftelhas.com.br/adm/Editor/ckfinder/userfiles/files/wominuvedowakomagigosir.pdf
    • http://freemansphotography.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cf9ea0afa48---mugupasamepurukowazozota.pdf
    • http://www.oknookna.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160e8aaad46807---nolikefus.pdf
    • https://www.freshstartdigitalmarketing.com/wp-content/plugins/super-forms/uploads/php/files/1b4482e881d3509d593b8c45cc12914b/28498013949.pdf
    • https://www.sodigital.it/wp-content/plugins/formcraft/file-upload/server/content/files/160a41feece0d2---26282034647.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=los+primeros+martires+de+la+iglesia+catolica
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001a814.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A814 16792 bytes
font_01_sfnt_off0001c02b.bin
a851dabe0284fce64c0d2fadbc56f10a1aabc00cb11e97e034fbc04f00ba560b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C02B 10712 bytes
font_02_sfnt_off0001d891.bin
1b99c4c7787b01ecea350d54f1cc1301ea5deb947f471681cb1a01d7640f682a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D891 17752 bytes