Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b15155f7dfb8e49…

MALICIOUS

PDF

68.6 KB Created: 2021-06-24 20:44:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e98a620cdf187091a5f3c8f3924450f1 SHA-1: fdd300cb9f2f6f66d3d93c20a84f3f66c93729d6 SHA-256: 6b15155f7dfb8e491d950d5afaabd77dd8ab56b3a68f563fef7d7d628ba92deb
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious. It contains numerous URLs, many of which point to compromised CMS upload storage or disposable hosting, suggesting a link farm designed to distribute malicious files. The presence of 'utm_term=download velamma comics pdf' in one URL indicates a lure to entice users to download content. No scripts were extracted, but the overall structure and URL patterns are indicative of a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://feynburg-uhren.de/uploads/wemafido.pdf
    • http://fantalife.nl/userfiles/file/88717412226.pdf
    • https://www.pal-kont.hu/wp-content/plugins/super-forms/uploads/php/files/8d0f96af844ce35c8a8d13b6ff1edb17/33653388361.pdf
    • http://arohitourandtravels.com/userfiles/file/17576281711.pdf
    • http://www.brennholz-heinlein.de/wp-content/plugins/formcraft/file-upload/server/content/files/1606cfd5c3d2f7---71504075037.pdf
    • https://senzedigicraft.com/wp-content/plugins/super-forms/uploads/php/files/51d1e1e578d07d921e6853f740ef5345/dazosirig.pdf
    • https://118highschool.am/wp-content/plugins/super-forms/uploads/php/files/7e6d89e6348db9ae71d1151b67d87806/37032249847.pdf
    • http://uat.ideadunes.com/projects/ideadunes-portfolio-site/wp-content/plugins/formcraft/file-upload/server/content/files/16076c3e4d5bcb---75761925805.pdf
    • https://www.baptistenhardenberg.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160a0eba8c81c7---57451103004.pdf
    • http://westleyden72reunion.com/clients/4/46/469dc9162705cbff2d1fbe132f144f37/File/xiguvelusuziw.pdf
    • http://www.maoles.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a2acaba9cbd---busesa.pdf
    • https://cosalesrep.com/wp-content/plugins/super-forms/uploads/php/files/886a3cdd1cf1d428d1d1c77cf26beed4/32058307683.pdf
    • https://aartipalette.com/userfiles/file/rawefamurita.pdf
    • http://dok-vo.ru/userfiles/file/mamabisesineset.pdf
    • https://action-roofing.com/wp-content/plugins/super-forms/uploads/php/files/971495d083ee06774fc9aa2e21016291/60960348104.pdf
    • http://placc.info/up_image/fusiwabadeb.pdf
    • http://beachhigh65.com/clients/879402/File/11027380823.pdf
    • http://www.communityheroesproject.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607f17e242d06---mobunadididopedipudi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=download+velamma+comics+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ba0a.bin
9d2d2c82f2bb2f9ef8b6f11fc1e657c0286adcd9f83ecd5893ea16642b73b864
pdf-font-stream PDF embedded font (sfnt) at offset 0xBA0A 3064 bytes
font_01_sfnt_off0000c4d5.bin
3b7ce71b6ce277792bdfd8de9fc35788c50ee607c7e9ce2784f2fa735ed0e8b1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC4D5 5356 bytes
font_02_sfnt_off0000d718.bin
5e98e0cd98d3dc7dea1cc0812c7a863284b6c5a3e0beb2321266c4eae398307b
pdf-font-stream PDF embedded font (sfnt) at offset 0xD718 2848 bytes
font_03_sfnt_off0000e270.bin
07e5874376238b466522110851e2110f1723bbc6012cf1cb10a777745013e5d9
pdf-font-stream PDF embedded font (sfnt) at offset 0xE270 9988 bytes