Malicious PDF — malware analysis report

Static analysis result for SHA-256 7067671ee89cd85f…

MALICIOUS

PDF

79.5 KB Created: 2021-06-28 03:42:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-09-13
MD5: f654990e9e87484653cbfacd6471a18e SHA-1: aaf078b084d97281510610c7d36566474998bdf9 SHA-256: 7067671ee89cd85f9de7a8e74f208a93e62dd7cc04c63d18b65c41449312ceca
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged by multiple heuristics as malicious, including a high-confidence ML classifier and ClamAV detection. It contains a link farm pointing to compromised CMS upload storage and other disposable hosting, suggesting a phishing or malware distribution attempt. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic indicates the document likely provides instructions to download a password-protected archive, a common tactic to evade gateway scanning.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9960

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://upperdublin1970.com/clients/3/3b/3b2fb281f4756d03d37a29c41a8c1d95/File/56220308821.pdf In PDF document text
    • http://chiangmai-clean.com/user_img/files/44205757953.pdfIn PDF document text
    • https://holzhaus-suedtirol.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607ebc1e9978a---63639291648.pdfIn PDF document text
    • https://dazzlin.co.uk/wp-content/plugins/super-forms/uploads/php/files/e90aeea93474ebab5f8bccfcf207d62a/jeroxiwomemezafupabepu.pdfIn PDF document text
    • http://adaviestransportltd.com/userfiles/file/80709802103.pdfIn PDF document text
    • https://impariant-club.ru/wp-content/plugins/super-forms/uploads/php/files/f95b9782836497e2eacc691e156234e1/79677018622.pdfIn PDF document text
    • https://www.tessilgiada.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607a14183e0bb---92505142751.pdfIn PDF document text
    • http://cn-junsheng.com/upload/file///20216715813905.pdfIn PDF document text
    • http://sintellect.ru/Repository/file/17244622746.pdfIn PDF document text
    • https://masterok-kovka.ru/wp-content/plugins/super-forms/uploads/php/files/8c8175614f83d9f7fb8faddaa923e0c6/12599914064.pdfIn PDF document text
    • http://themultifold.com/wp-content/plugins/super-forms/uploads/php/files/d3fnfi52p1gjav52g4c3pk8a94/dazigerufuvozodasuraga.pdfIn PDF document text
    • https://batdongsandothanh.vn/luutru/files/45075267137.pdfIn PDF document text
    • http://www.catalogodecineargentino.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c59b997dd6---67073817146.pdfIn PDF document text
    • http://drvision.org/wp-content/plugins/formcraft/file-upload/server/content/files/160b2db500fb44---79446706577.pdfIn PDF document text
    • https://njsolarpower.com/wp-content/plugins/super-forms/uploads/php/files/1740472e4aa3f84eaafdea292327fc5c/79512247953.pdfIn PDF document text
    • https://zivotzaokny.eu/res/file/pusidisoravenanaruk.pdfIn PDF document text
    • https://astoriareiki.com/wp-content/plugins/super-forms/uploads/php/files/9deb573f490b9a19c8367b5ad62f8199/zulufujepuzutesotipuda.pdfIn PDF document text
    • http://timeyear-v.com/userfiles/file/gonudofotu.pdfIn PDF document text
    • http://tramtronbetong.com/uploads/userfiles/file/tuzetim.pdfIn PDF document text
    • http://kimyasaldubeller.com/upload/ckfinder/files/64012963081.pdfIn PDF document text
    • https://relleno-acidohialuronico.com/wp-content/plugins/super-forms/uploads/php/files/ca7be7aeb2083d0946f628e823760df4/dizofakesej.pdfIn PDF document text
    • http://cathayred-csr.com/img-cathay/files/wejawavefekerexig.pdfIn PDF document text
    • https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/36b7695c6e30dc840d1e7df82a0d37de/lewoliwunusefof.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=online+multiple+word+to+pdf+converterPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d2da.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD2DA 17224 bytes
SHA-256: 888640cfb9eeed674bb61226ee9f2062a935272a572103ae843344392b6c09ef
font_01_sfnt_off0001000b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1000B 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00011822.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11822 10728 bytes
SHA-256: 67d3e2b7e00573b9b444bda7a1399b6755f4cd3022ff96a9770cdc087543e4cc