Malicious PDF — malware analysis report

Static analysis result for SHA-256 7faf7cd5d8078949…

MALICIOUS

PDF

107.4 KB Created: 2021-05-07 09:09:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 60fe1712c3ff906c3b616e16c54ef8b3 SHA-1: 42bcdf3e325e47a241aacbe7d50a5d8d03bd568d SHA-256: 7faf7cd5d8078949dde39a773111668a8deda08f5cd22e61a269b5e09a4198e2
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The sample was detected as a phishing trojan by ClamAV and flagged by an ML classifier. Heuristics indicate it contains external URIs and links to compromised WordPress upload storage, suggesting a phishing lure. The embedded links likely lead to further malicious content, such as other PDFs or executables, hosted on compromised websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8159

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://alutat.com/data/file/31853527768.pdf
    • https://apparel.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/42807c2dc41c04647fc9c122bb4e449f/malegivugutafigasarugazi.pdf
    • https://www.cdscabling.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16086f92629540---jabubutugeledugiguwupu.pdf
    • http://argra.rs/wp-content/plugins/formcraft/file-upload/server/content/files/1608438ec79d9b---senikabuwezojapafuzodasal.pdf
    • http://www.aportecnica.com/imagenes/editor/file/50579209513.pdf
    • https://glowskincare.net/wp-content/plugins/super-forms/uploads/php/files/e99b57eff3bd579f45683337e86e1dd7/pinobesupiteg.pdf
    • http://c2mag.com/wp-content/plugins/formcraft/file-upload/server/content/files/160817eec80b1a---77042892017.pdf
    • https://www.sacda.org/wp-content/plugins/super-forms/uploads/php/files/b7mal3gf4ak1v98l7ol8ofisp4/gosarigagawonuniti.pdf
    • https://braviengenharia.com.br/wp-content/plugins/super-forms/uploads/php/files/olftmpv9iij1rrhhi7vppteeps/dedokewu.pdf
    • https://www.hintonassociates.com/wp-content/plugins/super-forms/uploads/php/files/3bb1571b74f858af8eb2112a76f8a9a6/42922578075.pdf
    • https://sellerflows.com/wp-content/plugins/super-forms/uploads/php/files/e36897897c4ee997a39855db6a118e5a/25758607661.pdf
    • https://www.eoluk.com/wp-content/plugins/super-forms/uploads/php/files/luh02pc2tf13qiecfkrb1oojtn/wipagixuxanizopiga.pdf
    • https://www.3dreamchurch.com/wp-content/plugins/super-forms/uploads/php/files/fea6231ac48a078cf925bf5731024398/87000529058.pdf
    • http://adabaskimerkezi.com/upload/file/guwekubeni.pdf
    • http://www.phonefixcomo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ec99230f71---tekegegetevawuxotupufa.pdf
    • https://www.asahinadigital.com/wp-content/plugins/super-forms/uploads/php/files/12kqkvf2g13uofkfn0av51gv4r/94477710232.pdf
    • https://adiwirawanbali.com/wp-content/plugins/super-forms/uploads/php/files/cd18543d29d82c7d7a77fd5bb261fc01/71336122835.pdf
    • https://aslimitada.com/userfiles/file/wiwewixusuwamutixipe.pdf
    • https://thesaddlebank.com/wp-content/plugins/super-forms/uploads/php/files/ja04uos13e0likpdsa8dh9p5qa/zorivupuminenetavozi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=flask+render_template+utf-+8
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb89.bin
4970a3764f4b8389db4a4726db42a29ca8e8eacb2763c60e625a2c48b25298b0
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB89 53768 bytes
font_01_sfnt_off00019d9e.bin
bc5326d4cfbfca122265438750ed69f3ffb1d92a8911e4d7699a19d3721aaa77
pdf-font-stream PDF embedded font (sfnt) at offset 0x19D9E 5464 bytes