Malicious PDF — malware analysis report

Static analysis result for SHA-256 859f41c676ce34c6…

MALICIOUS

PDF

95.0 KB Created: 2021-07-02 13:55:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-09-14
MD5: bd219da580525176374aef8ad72af678 SHA-1: bef34bffb333d84aa89fccb5561ae7db23145548 SHA-256: 859f41c676ce34c65dc062edacdd5f7d3be8f4e6a7bc08aef6f48aeb77b404ae
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The sample is identified as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains numerous embedded URLs, many pointing to compromised WordPress sites and disposable hosting, forming a link farm. This structure suggests the PDF's primary purpose is to redirect users to external malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9820

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.hospedeagora.com.br/wp-content/plugins/super-forms/uploads/php/files/kmq10hvk9vbbsadf573m8o3clj/vajiferesemadusalesuka.pdf In PDF document text
    • http://www.radioemka.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608a0546186f7---33185607042.pdfIn PDF document text
    • https://maloneslandscape.com/wp-content/plugins/formcraft/file-upload/server/content/files/160da7c0ce455d---zesewobuzaxafa.pdfIn PDF document text
    • https://apparel.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/1fa10b14cc271eb26f6c34c2082efadf/50410892473.pdfIn PDF document text
    • http://cariboohose.com/userfiles/file/61511549125.pdfIn PDF document text
    • http://www.leesii.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608656cb32c74---24904656014.pdfIn PDF document text
    • https://agrachoff.ru/wp-content/plugins/super-forms/uploads/php/files/0b09e84399df0f74d22e0eec3ff24840/ximoruzikexope.pdfIn PDF document text
    • https://www.auditek.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1607d218692fee---56625566114.pdfIn PDF document text
    • https://estigotours.com/wp-content/plugins/super-forms/uploads/php/files/c1a23a520c10b5a374b54bf2fff773b7/sinefakofef.pdfIn PDF document text
    • http://basyapiemlak.com/yukleme_klasoru/userfiles/file/tulinofif.pdfIn PDF document text
    • https://samoinstitute.mn/uploads/assets/file/3241651602.pdfIn PDF document text
    • http://xperion.hu/wp-content/plugins/super-forms/uploads/php/files/3f2627fafed5617a8cad0b934bb76b05/58037772919.pdfIn PDF document text
    • http://www.catalogodecineargentino.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607689220a84b---ludekelivi.pdfIn PDF document text
    • http://omniatel.it/wp-content/plugins/formcraft/file-upload/server/content/files/160afb81ae9364---79447525625.pdfIn PDF document text
    • https://moniimpex.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607604dcaae9a---34238755952.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a6f5e473fab---nukidoxomogetiwolemeka.pdfIn PDF document text
    • http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/1608f48269e77d---14541153344.pdfIn PDF document text
    • https://nationalcardsolutions.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609834b240b9f---xekifaxanudum.pdfIn PDF document text
    • http://157.230.241.115/image/upload/File/38120563262.pdfPDF link annotation
    • https://agilitynd.com/wp-content/plugins/super-forms/uploads/php/files/bb9252ec6bfab23994eaabe4d5e9f4fa/xakixinuzofivotodozalepe.pdfIn PDF document text
    • http://www.leesii.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078584c9c44e---kibugav.pdfIn PDF document text
    • https://northstarexecutivesearch.com/wp-content/plugins/super-forms/uploads/php/files/e27fa969f4511078a5aeba342f883f2a/noxofafepozoxasigin.pdfIn PDF document text
    • http://www.zulfugar.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609c43ac52cd6---62199522569.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b63577b4220---28702086143.pdfIn PDF document text
    • https://www.alarisusallc.com/wp-content/plugins/super-forms/uploads/php/files/ceb2efbe9a9a30dcdb012e34d4476fb2/pigusirenabivibutopopolad.pdfIn PDF document text
    • https://sipare.com.ar/wp-content/plugins/super-forms/uploads/php/files/6smop7lgg6s24c3fdsu3p1npqs/gedukapevokitiwepijub.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=class+10+chapter+2+economics+question+answerPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010f3c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10F3C 17264 bytes
SHA-256: f4203e6eb6b660690d6424b98c34c176cb1b535d3a6c70f2a1d3bc7e6e90a6c9
font_01_sfnt_off00013bd2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13BD2 11296 bytes
SHA-256: a66ef71e90cfc75f41ccb4868c0cfa813483d1055d601f771413e978934bc51d
font_02_sfnt_off00015653.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15653 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1