Malicious PDF — malware analysis report

Static analysis result for SHA-256 73df0cb0963a4c7d…

MALICIOUS

PDF

250.0 KB Created: 2021-06-29 09:58:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 819ed919a32a13fb3a805b1e5b65dd0c SHA-1: 30d5ec9f1f29bfa0fd66dd8bfbf9e3ab2cfa4e29 SHA-256: 73df0cb0963a4c7d3d208e29071ac567841701f5bd55b48a455ec0629b22ae1d
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs, with a significant number pointing to compromised WordPress upload storage, indicating a phishing or redirection attempt. The ML classifier and ClamAV detection strongly suggest malicious intent, likely to lead users to further malicious content or downloads. No scripts were extracted, but the embedded links are the primary attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8372

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://drmiamiconnect.com/wp-content/plugins/super-forms/uploads/php/files/5979360ca1305a639f92f54ad5048759/niror.pdf
    • https://dacoma.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1609b548d05df5---29981935130.pdf
    • http://sarljarry.fr/userfiles/file/jumajenuvawomubuxefavufo.pdf
    • http://omgmediatank.com/userfiles/files/29122021880.pdf
    • https://www.aserspa.net/wp-content/plugins/super-forms/uploads/php/files/8k3g7vs98ggvcg6ts3kh8n9rg6/mujiradixinu.pdf
    • https://sgdivorcelawyers.com/wp-content/plugins/super-forms/uploads/php/files/dd36bbe34deef393cf8f4d13cefd6936/8065150436.pdf
    • https://wilsonbarrera.com/inicio/wp-content/plugins/formcraft/file-upload/server/content/files/160a7377c77b66---xabofazupa.pdf
    • http://akbmodel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bd360f51e00---76732782225.pdf
    • http://www.suffaheducation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bbdd3bcdd65---dusubowajuxoz.pdf
    • https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c1b33974388---9823757636.pdf
    • http://alibabashipping.com/userfiles/file/25293626175.pdf
    • http://reclaimsplus.com/wp-content/plugins/super-forms/uploads/php/files/32175ba9237f1ebf830d2e096a268d08/50349241781.pdf
    • https://themodernla.com/wp-content/plugins/super-forms/uploads/php/files/14efb9f98d0ba0748ddc90965e0c2986/96697069183.pdf
    • https://oknoplus-omsk.ru/wp-content/plugins/super-forms/uploads/php/files/8f8c799cb8e87e12f72ae76eba38140e/muwunesuxogewogatulus.pdf
    • http://conwaychristian.org/wp-content/plugins/formcraft/file-upload/server/content/files/160ab67c0c81ad---85174153714.pdf
    • http://www.oknookna.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160c38fe4dd147---zorajenekakowujabexolo.pdf
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608d4f1acd065---787692956.pdf
    • https://gk-termopanel.ru/wp-content/plugins/super-forms/uploads/php/files/8f7af9d089d28a8eec6c607dae76cb38/gitugezotunidexemejutito.pdf
    • http://ufnk.fr/app/webroot/files/file/70455207610.pdf
    • https://kuechentreff-schmid.de/wp-content/plugins/super-forms/uploads/php/files/s1bp6n556er2k77tu1tenvnc0s/xegegosukukad.pdf
    • https://baodinhsolar.com/wp-content/plugins/super-forms/uploads/php/files/ps85ucuv4vnu4h5ngob8mt1635/28399178835.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/FevRqgeaUVY/uplcv?utm_term=hyyh+the+notes+pdf
    • http://irodori.kir.jp/files/file/58187663801.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000355af.bin
96217f53ca691ac84aa71cf1a589fa981564b57442dffad2120ed28abd3d3203
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x355AF 33724 bytes
font_00_sfnt_off000313bd.bin
f08daf766210212461396014d232098066a37aee693821fe56458767746da4f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x313BD 13308 bytes
font_01_sfnt_off00033d9e.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x33D9E 16792 bytes
font_03_sfnt_off00039039.bin
786d1595fa37af579fadcda5496821583b21b6f2d775c2d39f29b5955929f70a
pdf-font-stream PDF embedded font (sfnt) at offset 0x39039 18396 bytes
font_04_sfnt_off0003c0fb.bin
227fb24de211dab57ea2b440a2e6d214b69244a2fdea2d836fdb9e83d11dfaa2
pdf-font-stream PDF embedded font (sfnt) at offset 0x3C0FB 10300 bytes