Malicious PDF — malware analysis report

Static analysis result for SHA-256 80f7c1b32ffa3feb…

MALICIOUS

PDF

219.7 KB Created: 2021-07-26 06:47:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-05
MD5: 4822701025bb4149e447d4e406aabcb2 SHA-1: 81aabe402bd5b40db578c8206c4c834424a8272e SHA-256: 80f7c1b32ffa3feb4ea09e7cf0aef77ec3068cbbcae1584b37934a6228f019de
166 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document exhibits characteristics of a phishing lure, specifically prompting the user to install a browser extension or update. This is a common social engineering tactic to facilitate credential theft or malware installation. The presence of multiple links pointing to compromised CMS upload storage and the ML classifier flagging the PDF as malicious further support this assessment. No scripts were extracted, but the document's structure and embedded URLs suggest a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9828

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://brmhn.com/userfiles/file/20210723115359_m425rj.pdf In PDF document text
    • http://bezpieczna-strefa.pl/wp-content/plugins/super-forms/uploads/php/files/3c86188ff1e84bd028cfbc4b0e60eb24/80589674459.pdfIn PDF document text
    • https://fotokeramika.bg/userfiles/file/17304775420.pdfIn PDF document text
    • http://kowel.com/ckfinder/userfiles/files/1626692028.pdfIn PDF document text
    • http://short-story.ru/upload/file/jafuterifisasevivif.pdfIn PDF document text
    • https://prosegik.com/wp-content/plugins/super-forms/uploads/php/files/be12c8c7b6a6e1510f6fec5bff281213/goratubi.pdfIn PDF document text
    • http://villaturri.it/wp-content/plugins/formcraft/file-upload/server/content/files/1609a8b4468a9e---ponifanedigepisijufikuzo.pdfIn PDF document text
    • https://www.etbsupplies.com/wp-content/plugins/formcraft/file-upload/server/content/files/16084b7dd1a763---46441335159.pdfIn PDF document text
    • http://altinay-law.com/images/file/46257811016.pdfIn PDF document text
    • https://okud-istra.hr/userfiles/file/61562052072.pdfIn PDF document text
    • https://aljazeerahdrilling.com/userfiles/files/woguziwukofo.pdfIn PDF document text
    • https://sharzh-ufa.ru/wp-content/plugins/super-forms/uploads/php/files/fd1ec90f7bd56cc01ca14236cf28a0ca/65393623655.pdfIn PDF document text
    • https://envomask.com/wp-content/plugins/super-forms/uploads/php/files/e463ef74697bf8d5286c51133406721c/rasizemubavu.pdfIn PDF document text
    • https://ladychief.com/wp-content/plugins/super-forms/uploads/php/files/bf4acee6ba17e30d026e84a2b9788d44/7799876245.pdfIn PDF document text
    • https://monocroma.it/wp-content/plugins/super-forms/uploads/php/files/55c10a92791049e599092d281c60747d/vidipowumamubojujaki.pdfIn PDF document text
    • http://rheinmotel.com/userfiles/file/bixoxudasa.pdfIn PDF document text
    • http://furniture83.com/upload/files/57354371435.pdfIn PDF document text
    • https://realestateconnect.biz/wp-content/plugins/super-forms/uploads/php/files/j6mgg6vu7pvm4e5c2qtalsigr6/88608911514.pdfIn PDF document text
    • http://dinskayarealty.ru/media/file/loninexilesolim.pdfIn PDF document text
    • http://inwallendorf.de/userfiles/file/61411583493.pdfIn PDF document text
    • http://www.unidacardoso.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609d44dd8addd---vuzali.pdfIn PDF document text
    • http://designbeginnings.com/upload/file/47034448892.pdfIn PDF document text
    • https://www.xcelsus.de/wp-content/plugins/formcraft/file-upload/server/content/files/160ec424b4b80c---xinezak.pdfIn PDF document text
    • http://xn--80ackbssfuieecff0e8c.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/p7ei17gsmr92d81at3m4fb7gq7/xutiferibikozop.pdfIn PDF document text
    • https://www.erenang.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608472c875aee---fedelukunudaxas.pdfIn PDF document text
    • https://guijek.com/userfiles/file/rosivemuda.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/BvfzZFkJO3s/uplcv?utm_term=computer+architecture+a+quantitative+approach+5th+edition+solutionsPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002f8d1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2F8D1 11256 bytes
SHA-256: 9c0cb870fa68a4ed086a35a5dc123a77a5ecb52d3846b571a2dd3b6021dbedfb
font_01_sfnt_off000312e0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x312E0 19876 bytes
SHA-256: 8201c80ea998801c1dcdbbe9cd9d15a71e7cc54d9c573df070d5d66f41ec7876
font_02_sfnt_off00034755.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x34755 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1