Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fd02b1734e06fe5…

MALICIOUS

PDF

107.2 KB Created: 2021-07-04 02:11:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: ae76b69cda27ff47ce23c23f1c49afce SHA-1: 6601b300d65fb41c1974e994c6a02a11e6dbb32f SHA-256: 7fd02b1734e06fe5438f2f0e7e9aca7cf9414c9f879803f08946bab3d678f25d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection and an ML classifier. The document contains a link farm with numerous URLs pointing to potentially compromised websites or disposable hosting, suggesting an attempt to redirect users to malicious content. While no scripts were explicitly extracted, the PDF structure and embedded links are indicative of a phishing or malware distribution lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9746

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://atraba-holding.com/userfiles/file/9884763582.pdf
    • https://yournew.site/wp-content/plugins/super-forms/uploads/php/files/sopq0j72rfrsboudmh8eknads7/241100678.pdf
    • http://kcde.kr/userfiles/file/51166490778.pdf
    • https://www.adelaarenergy.com/wp-content/plugins/super-forms/uploads/php/files/ftd6122rfuictnbfpf8rj210uh/porutaxeladupogusuj.pdf
    • http://www.louthadventures.ie/wp-content/plugins/formcraft/file-upload/server/content/files/1607e3bf5c58dd---91064571489.pdf
    • http://yuha.be/_files/file/86824386299.pdf
    • http://joewhitefamilysite.com/clients/59967/File/nawipuf.pdf
    • http://riph.pl/userfiles/file/65591261843.pdf
    • http://haciogullari.com/depo/sayfaresim/file/36857002247.pdf
    • http://bmsorganica.com/userfiles/file/mafozijakobabago.pdf
    • http://www.ponderosafestival.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d95a35ad2e0---mefuwabotosetewa.pdf
    • https://socialchangefactory.org/wp-content/plugins/super-forms/uploads/php/files/69b3b93f6094167c7c4d06b4c52f5c7b/71677819679.pdf
    • http://www.altrus.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1608dd7b11f302---jafemeruxirewanezo.pdf
    • https://hartwellcook.com/wp-content/plugins/super-forms/uploads/php/files/32a2fe668a9d0e76c12329e669b25b6e/65723927454.pdf
    • http://archiprojektai.lt/app/webroot/uploads/userfiles/files/69802108570.pdf
    • https://2acontractor.it/images/file/wajezifobubugegodujiw.pdf
    • http://doorsatyrau.com/ckfinder/userfiles/files/wetoxirid.pdf
    • http://billsky.ee/files/file/97494219758.pdf
    • http://aksaxena.com/bpms/includes/fckeditor_uploads/userfiles/file/19947879055.pdf
    • http://bellezaeimagen.com.mx/wp-content/plugins/formcraft/file-upload/server/content/files/160858c06eeb22---45021923186.pdf
    • http://andrelandberg.com/userfiles/file/mudagogovawowimiximunub.pdf
    • http://dienlanhlongan.com/upload/files/xizegegizeto.pdf
    • https://www.carlosfunes.es/wp-content/plugins/formcraft/file-upload/server/content/files/160bc71022c39d---dovak.pdf
    • https://feedproxy.google.com/~r/skout/mBVl/~3/FevRqgeaUVY/uplcv?utm_term=ghost+in+the+shell+sac_2045+watch+online+free
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00012f06.bin
fe293d05a8c476d6109a9eac0c3b20ab5b47a53eb96d228754304d8ba525f00d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x12F06 21024 bytes
font_00_sfnt_off0000fd0b.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD0B 16792 bytes
font_01_sfnt_off00011522.bin
0d62f31a759008f29dc70d7a95c518758ec0b19635d60a540170e11b6054f19f
pdf-font-stream PDF embedded font (sfnt) at offset 0x11522 11044 bytes
font_03_sfnt_off000152dd.bin
8bbaf85b3e471d0c536b2b43cb9d282befa9f14d9e8914878575f33954f15ae8
pdf-font-stream PDF embedded font (sfnt) at offset 0x152DD 6304 bytes
font_04_sfnt_off0001694e.bin
7e28d4783b8740a5d0a7973e4cf0d15e0efae4b14a0204da89497cee3432f753
pdf-font-stream PDF embedded font (sfnt) at offset 0x1694E 21444 bytes