Malicious PDF — malware analysis report

Static analysis result for SHA-256 88a19a16255bb4e8…

MALICIOUS

PDF

124.2 KB Created: 2021-07-04 08:04:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: b0be7fbb0678ac1fdba4cebcd04dd4a8 SHA-1: 65337a33ec0eccb44d92a5dd98f4c9341033f71e SHA-256: 88a19a16255bb4e8aba772f38a0d7d73ab46f92c3b061d1d30beb9721f41d3d8
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document exhibits characteristics of a malicious invoice or payment lure, as indicated by the 'SE_INVOICE_LURE' heuristic. It contains numerous embedded URLs pointing to compromised WordPress sites and disposable hosting, suggesting an attempt to distribute further malicious content. The ML classifier strongly flagged this PDF as malicious, and the presence of external URIs further supports its malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 6

  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://wastran.ru/uplcv?utm_term=tds+challan+281+excel+format+download
    • http://www.qookspot.kitchen/wp-content/plugins/formcraft/file-upload/server/content/files/16097c6781eeb7---1772305953.pdf
    • http://sunnysideclassof64.com/clients/a/ac/acc4ccb49d7935ca36198347b895393e/File/kegugodutifas.pdf
    • http://banhangcongnghe.com/upload/FCK/file/zesowasinilajulugujowa.pdf
    • https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096c05d6fbff---92599759279.pdf
    • http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/42f14fa83eb9122c9cf0ce979fe384a5/domadaw.pdf
    • http://udokutscher.de/gfx/userfiles/files/raburanofifaxiziba.pdf
    • https://asiaviews.org/wp-content/plugins/super-forms/uploads/php/files/qg8tstr1dm379kgt8ckbvgrpl6/tujatujek.pdf
    • http://eduomania.com/wp-content/plugins/formcraft/file-upload/server/content/files/16091f2c87f30a---75721425215.pdf
    • https://webtraffic.ch/wp-content/plugins/super-forms/uploads/php/files/mkn0cm2i30gpa0u3c8idjvahcn/52641430202.pdf
    • https://www.toptalentusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/160761cfa179b4---waziduguderobumefamotenu.pdf
    • http://fmafirm.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/80082252826.pdf
    • https://pezenasenchantee.fr/userfiles/file/35420366529.pdf
    • http://www.caslyn.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160bc56478758c---fivuwokowokivukal.pdf
    • http://bochosushi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074188cab8cd---28961167481.pdf
    • http://soepcentrale-dekeyser.be/userfiles/file/66337461417.pdf
    • http://dobrasekacka.cz/userfiles/file/sadarumijabi.pdf
    • https://www.havanasalsa-dance-tours.com/wp-content/plugins/super-forms/uploads/php/files/bc3ce0d3dc8532e66f5029c926696c71/vofabokixifakoz.pdf
    • http://seamcc.com/UserFiles/files/bopadoparik.pdf
    • http://loveperfectionschool.com/upload/file/69706252412.pdf
    • http://c2ctrading.org/cms_upload/files/45816603467.pdf
    • https://2greenchicks.com/wp-content/plugins/super-forms/uploads/php/files/305228457b2f9bd8b21abda72ea9d460/zodux.pdf
    • http://volamtuyetthe.com/userfiles/file/jovamasovetiwirawolanokox.pdf
    • https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16086fce9c3e8b---nesivijekekisozutelije.pdf
    • https://advicezone.org.uk/wp-content/plugins/super-forms/uploads/php/files/oimot296i3fkfvvmo6e8k2og75/mefosetutovimalulog.pdf
    • http://koovappadyscb.com/ckfinder/userfiles/files/79186412672.pdf
    • https://hpsoft.shop/upload/files/16093504374.pdf
    • http://americusfelderfamily.com/clients/0/0c/0c5e5e27a4da9db51eb23c24aa0fa274/File/gafepiropevetojak.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018530.bin
85ed3225ac361466dd0e037f2803f18b6708b5046a650afdb550c2a0e1893da3
pdf-font-stream PDF embedded font (sfnt) at offset 0x18530 11180 bytes
font_01_sfnt_off00019f5d.bin
c3c4ac578c8722a009996b6d5c36dbdf377145300278146bee83e345fbb9f47b
pdf-font-stream PDF embedded font (sfnt) at offset 0x19F5D 16952 bytes
font_02_sfnt_off0001cb0f.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CB0F 16792 bytes