Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d11c15e86619495…

MALICIOUS

PDF

101.8 KB Created: 2021-07-07 12:56:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 467f86a48bd49b1330ab5ae3a786f41d SHA-1: a32c5a6df1c83473f32df2e78dd66b3e2c70dcd7 SHA-256: 6d11c15e86619495cd6d155a56da5e86cda31c0c99b8d8bb9211d7b55757a15e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains numerous links, many pointing to compromised WordPress upload directories, suggesting it's designed to lure users to malicious sites. The PDF itself does not contain readable content, but its structure and embedded links indicate a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9253

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.mediacomriccione.it/wp-content/plugins/formcraft/file-upload/server/content/files/1608cab3f3d8b8---29607988888.pdf
    • https://inclinedigital.com/wp-content/plugins/formcraft/file-upload/server/content/files/160872101af404---kirefotajigepevinefojox.pdf
    • https://maydongy.com/wp-content/plugins/super-forms/uploads/php/files/7h8p4qstkmhf6ha8hhju18l7s3/66074526463.pdf
    • https://sygimportaciones.com/wp-content/plugins/super-forms/uploads/php/files/sovmgt3vjc59mhuvmbspdt76b1/97136481186.pdf
    • http://pneusmarene.it/images/file/92357782078.pdf
    • http://3handseg.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608dc0edb79c7---jikozofinujisowesumojapi.pdf
    • http://alemotta.com/resources/original/file/84740769395.pdf
    • http://emannsltd.com/userfiles/80993620472.pdf
    • https://3dreamstudios.com/wp-content/plugins/super-forms/uploads/php/files/c55a09f4389939cea4ab05b1686f60dc/kanenowa.pdf
    • http://bestbelly.org/content/files/files/47887031674.pdf
    • https://comodee.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b04171a635b---liluxa.pdf
    • http://www.lavalledesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ae467ee63ed---votugipakasune.pdf
    • http://elmiraclassiccountry.com/wp-content/plugins/super-forms/uploads/php/files/2runopnuki5m0l868npeotc403/mefurekipiradoma.pdf
    • https://apexforestservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608637da7bf6c---95775839703.pdf
    • https://autoschiller.de/wp-content/plugins/formcraft/file-upload/server/content/files/160c45e7d45ba3---titawaru.pdf
    • http://gekon.net/userfiles/file/73453856825.pdf
    • http://pericosrentcar.com.mx/wp-content/plugins/formcraft/file-upload/server/content/files/1608840b9eb05e---puwoxanupelinoxetovopalix.pdf
    • https://hoffmanowska.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1608b1e7abf152---kafijazo.pdf
    • https://www.thecandystoresudbury.com/wp-content/plugins/super-forms/uploads/php/files/hiu0hfd622iq7c98boj1sh90qe/jerevusupuxaj.pdf
    • http://intestinalfortitude.org/clients/0/0c/0cf504f131cb0201443a7bd449519f4a/File/48992339623.pdf
    • https://psfund.org/public/uploads/files/cms_files/rimesabegagurepazufike.pdf
    • http://www.sarajevo-inn-grunewald.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b8077b9df1d---38156009574.pdf
    • https://playgametoday.ru/wp-content/plugins/super-forms/uploads/php/files/550cba82f964ada8fce283811210e7e0/75589997380.pdf
    • https://www.kngroup.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cb5d2c990c---2584877566.pdf
    • https://husvagnsexpo.se/wp-content/plugins/formcraft/file-upload/server/content/files/160c547fed079b---maberokejopimulerug.pdf
    • https://open-call.fr/uploaded/files/bulafivavevonaxotu.pdf
    • http://noavarservice.com/ckfinder/userfiles/files/33961135596.pdf
    • http://www.unidacardoso.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160d2104c634a9---xiturozul.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/FevRqgeaUVY/uplcv?utm_term=definition+for+astonished
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off000165d5.bin
e5003f4dad864390df3246c3085db853a75478bf1d3b28aae95c266762ab7c03
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x165D5 19364 bytes
font_00_sfnt_off0000e037.bin
5be03f5e83caf79c64517f9e44601ca1b9f006b8aed3f6696ef2e16154e8d265
pdf-font-stream PDF embedded font (sfnt) at offset 0xE037 10408 bytes
font_01_sfnt_off0000f7b9.bin
4fa4e413397efed4dc1ece29968dae26206b5bbc1101fd65a9d777a7f326160e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7B9 29052 bytes
font_02_sfnt_off00013c82.bin
854a530c3af6c98ed55f23223a22e739043ba0679299febb2e7751fe97b59416
pdf-font-stream PDF embedded font (sfnt) at offset 0x13C82 4728 bytes
font_03_sfnt_off00014dc4.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x14DC4 16792 bytes