Malicious PDF — malware analysis report

Static analysis result for SHA-256 88280402463ab267…

MALICIOUS

PDF

205.0 KB Created: 2021-06-29 04:41:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 05cc88d33eb7b81b0e29f1ac89cb81c1 SHA-1: 55f9f052c372251abbfc378ca7755470e951a96b SHA-256: 88280402463ab267af505dde0bfebeee2b777efb90ae2b60e8d0588ccee8b826
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm pointing to compromised WordPress sites, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. Although no scripts were explicitly extracted, the presence of embedded URLs and the nature of the heuristic firings point towards a phishing lure designed to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8865

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://amirep.com/wp-content/plugins/super-forms/uploads/php/files/12fdf970ff02b5e7c75a5a681027327c/82534623208.pdf
    • http://nuraski.pl/wsg/userfiles/zebovajadileja.pdf
    • https://purebodycare.courses/wp-content/plugins/super-forms/uploads/php/files/msp69af1u6jbjgvhrce5v902p4/vupezeru.pdf
    • http://www.kissdocs.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160a7c5b620bc5---nulasebenapivusexuf.pdf
    • http://www.skupp.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1606f2b90d6b47---85949847214.pdf
    • http://jointrilogy.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ad09b5ec401---1977595480.pdf
    • http://penzionklara.cz/userfiles/file/ridabiferisalorome.pdf
    • http://skiflogistics.ru/userfiles/file/bonosunapajoxesu.pdf
    • https://nailseasupportgroup.com/wp-content/plugins/super-forms/uploads/php/files/9b636cb846cc636026f45282a41b55b8/gebokulowikaluwodujopoki.pdf
    • http://www.predoisiasociatii.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16090dc9407c1e---90359814321.pdf
    • https://ontime-taxi.kg/wp-content/plugins/super-forms/uploads/php/files/e49f84c132e492c33bd2d708a917db1e/62281246858.pdf
    • http://www.oknookna.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1607215d902413---dudivojobelebesisul.pdf
    • http://recamonde.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160d50410005f0---dimemopasapelewus.pdf
    • http://pusancard.com/userData/board/file/pakebugizetaza.pdf
    • http://www.majorisinvestimentos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160b3bf6a0842d---tiral.pdf
    • https://greenturtleproductions.com.au/wp-content/plugins/super-forms/uploads/php/files/5403510b8abd74c228532157935a369a/xabiwokap.pdf
    • http://spadhotel.com/basefile/spadhotelcom/files/zivevozeluwigisixadoket.pdf
    • http://accurateverdicts.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609c4023e9c99---jalamufuf.pdf
    • https://www.kalirich.com/wp-content/plugins/super-forms/uploads/php/files/rbr07jbqhukrtmmg1vjkuldft5/17891388584.pdf
    • https://tectrongim.com/uploads/files/31860929274.pdf
    • https://www.rydalmereprestige.com.au/wp-content/plugins/super-forms/uploads/php/files/4eifhnitbjqcvg1otaepd18asm/97640479121.pdf
    • http://mu-rrrc.com/userfiles/file/54130001524.pdf
    • https://aduanaldelvalle.mx/userfiles/file/18149426166.pdf
    • http://aelma.com/sites/default/userfiles/file/8184022513.pdf
    • http://capesociety.ca/uploads/files/98711888029.pdf
    • http://plusbateria.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b8e0fca94da---tugofarilareja.pdf
    • https://feedproxy.google.com/~r/skout/mBVl/~3/FevRqgeaUVY/uplcv?utm_term=passive+and+active+components+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00029693.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x29693 16792 bytes
font_01_sfnt_off0002aea5.bin
b67654135b729c37bddfcc5569e25ab2cc1b51607a264713866106ea46b3005b
pdf-font-stream PDF embedded font (sfnt) at offset 0x2AEA5 24844 bytes
font_02_sfnt_off0002ec79.bin
a025088f130756a92ca3f8b3354632bb3820378440df618410003fc350859a34
pdf-font-stream PDF embedded font (sfnt) at offset 0x2EC79 19904 bytes
font_03_sfnt_off00030d93.bin
a019032a580eda874da07ed74b19a910c79fb7833c9790e402f3351719eb1e1f
pdf-font-stream PDF embedded font (sfnt) at offset 0x30D93 10704 bytes