Malicious PDF — malware analysis report

Static analysis result for SHA-256 895f10003b9daa16…

MALICIOUS

PDF

97.8 KB Created: 2021-07-14 07:36:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-27
MD5: ecd5404ba1fe6b701fa3d435b893b9a5 SHA-1: 513c96992032944c3fa9101d896cc5f7e323fb80 SHA-256: 895f10003b9daa16ab5b78268b86b76db4bdcb5705cf9b947b9b2e8f1a1efb01
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file contains embedded JavaScript and a significant number of external URIs, many of which point to compromised WordPress sites. The ML classifier strongly indicated maliciousness. The embedded JavaScript likely serves to obfuscate or execute further malicious actions, while the link farm suggests an attempt to distribute malware or conduct phishing by leveraging compromised infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9800

Heuristics 6

  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lesfeesdelhetre.fr/upload/files/sasoje.pdf In PDF document text
    • http://studioassociatoemc.com/userfiles/files/natixe.pdfIn PDF document text
    • http://bortran.com/upload/image/file/20210530011255.pdfIn PDF document text
    • http://kondicionery-vidnoe.ru/upload_picture/file/46993873985.pdfIn PDF document text
    • https://associazionedynamica.it/uploads/file/17679063197.pdfIn PDF document text
    • https://bodwellassociates.com/wp-content/plugins/super-forms/uploads/php/files/4bf78137fb811d73ad8a62d140a42491/dumitibixo.pdfIn PDF document text
    • http://www.bash.cl/media/file/82261802282.pdfIn PDF document text
    • https://accesoriosalmayor.com/images/userfiles/file/xipeboduxupilekegexi.pdfIn PDF document text
    • http://www.ebsjosepirosamaria.com/wp-content/plugins/formcraft/file-upload/server/content/files/160da157e8769f---36058385386.pdfIn PDF document text
    • http://www.medical-psychology.gr/wp-content/plugins/formcraft/file-upload/server/content/files/16095b198bdcf8---50180278291.pdfIn PDF document text
    • https://ceadersvalet.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bed9275a664---damigumut.pdfIn PDF document text
    • https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/16090868a1e6b8---35887715116.pdfIn PDF document text
    • https://ohligschlaeger-berger.de/wp-content/plugins/formcraft/file-upload/server/content/files/160be1c706501a---nakuribeg.pdfIn PDF document text
    • http://burningspearmarketplace.com/js/ckfinder/userfiles/files/zotowinovivixifaxek.pdfIn PDF document text
    • https://agribusiness.pk/wp-content/plugins/formcraft/file-upload/server/content/files/160783022573ee---dirase.pdfIn PDF document text
    • http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/c7c0ac7a8908eeec3c5f4e705cacdcb5/65874366603.pdfIn PDF document text
    • https://christianboudreau.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a7d53b3ceeb---62765327600.pdfIn PDF document text
    • https://oneremote.ru/wp-content/plugins/super-forms/uploads/php/files/b60ac20feee515c914d5e65e75cd0b77/pozototexowidogegomid.pdfIn PDF document text
    • https://mecaniquekd.ca/upload/file/sesexojaj.pdfIn PDF document text
    • http://salonlomi.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160b89ac41dd79---xavijitegarijezetak.pdfIn PDF document text
    • https://neoville.ru/wp-content/plugins/super-forms/uploads/php/files/e4adf7cb08f0708d8e88b013d6dc21ed/metanekavodekuvo.pdfIn PDF document text
    • https://www.davinci.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160a01eeaddba0---91310963573.pdfIn PDF document text
    • https://beaufortbond.com/wp-content/plugins/super-forms/uploads/php/files/78a2f468ca170c3f1c4a9dc05203dc74/45811196122.pdfIn PDF document text
    • https://pasarantogeldua.com/contents//files/52382252074.pdfIn PDF document text
    • https://baxsporthorses.nl/userfiles/file/17571577811.pdfIn PDF document text
    • http://inlikeflintlogistics.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b7bfb589f6a---perizuzimixebakomutinumak.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=bram+stoker%27s+dracula+mina+and+lucyPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001191d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1191D 10924 bytes
SHA-256: 6cda6c8919c535ea7cc04f772858f585704b1ee06b7091d1e3fdf968bdd2998b
font_01_sfnt_off00013284.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13284 18012 bytes
SHA-256: ebe8f9cbd5ef2401c093d91dc8955a837a7ea60ac816dab80786b5392957075c
font_02_sfnt_off00016016.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16016 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1