Malicious PDF — malware analysis report

Static analysis result for SHA-256 8e93dfb1e1b485a2…

MALICIOUS

PDF

284.7 KB Created: 2021-08-08 13:13:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-05
MD5: f80b3778c819f83641a08aa362b1dbca SHA-1: d8d11aa6a6371c9fd7eaafb8aebda6dd4a138a58 SHA-256: 8e93dfb1e1b485a2049c117339fb0ebc1fabc0c321f30de0887e25423bcc445f
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. Numerous external URLs were extracted, with one specifically linked to a compromised WordPress upload directory, suggesting a phishing or malware distribution lure. The PDF structure and embedded URLs point towards an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8874

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://irlanc.ru/uplcv?utm_term=new+oxford+american+dictionary+pdf+download PDF link annotation
    • http://dtcguild.org/clients/80367/File/38781660689.pdfIn PDF document text
    • http://seventyfirstclassof69.com/clients/60772/File/sirawolakixazig.pdfIn PDF document text
    • https://drsaman.com/files/xivowitiru.pdfIn PDF document text
    • https://hiperaktivite.info/userfiles/files/jomasujonilaxoxiva.pdfIn PDF document text
    • https://hsegroup.ru/wp-content/plugins/super-forms/uploads/php/files/t1d6gkkk14lnllv543g2fn63r3/bepodizawul.pdfIn PDF document text
    • https://intelean.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609154be69d6f---rexevunofitakem.pdfIn PDF document text
    • http://yuanjen.com/ckfinder/userfiles/files/lumosugetituzekino.pdfIn PDF document text
    • https://eyestech.in/wp-content/plugins/super-forms/uploads/php/files/0d5q42157jemcns5oheip3s1nn/97874655642.pdfIn PDF document text
    • https://siroyensao.com/upload/files/bajanive.pdfIn PDF document text
    • https://taichielite.com/louis/taichi/ckfinder/userfiles/files/78017120657.pdfIn PDF document text
    • http://pvsystexperts.com/wp-content/plugins/super-forms/uploads/php/files/24bffigt73mn98u93rs0tnnte7/90647695792.pdfIn PDF document text
    • https://hcs1000.org/wp-content/plugins/super-forms/uploads/php/files/fecf6a1a0de3bf3d40ef5593ca21b6f0/45593571917.pdfIn PDF document text
    • http://tevukasveza.lt/ckfinder/userfiles/files/56973532811.pdfIn PDF document text
    • http://alpha-cp.com/userfiles/file/35466117479.pdfIn PDF document text
    • https://www.goldenplanet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1609b03c128b92---fofikaw.pdfIn PDF document text
    • https://aquaprosmart.com/userfiles/files/wivexir.pdfIn PDF document text
    • http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1610fa0c3259c9---figosog.pdfIn PDF document text
    • http://scriptonica.ru/files/files/gututuridatejebetode.pdfIn PDF document text
    • https://flvirginia.com/wp-content/plugins/super-forms/uploads/php/files/368d113ab98d8e98eae9ed125b5ae959/53661131116.pdfIn PDF document text
    • https://torgradio.ru/new/files/file/71137771276.pdfIn PDF document text
    • https://microfocus-realize2020mea.com/wp-content/plugins/super-forms/uploads/php/files/4ad881c12b4758c31ca619401ecac54a/3715968517.pdfIn PDF document text
    • http://synagoge-stommeln.de/ckfinder/userfiles/files/42529102433.pdfIn PDF document text
    • https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/df70198b1f4a50b38273b4ada725ca4e/lawipa.pdfIn PDF document text
    • https://aldea.work/wp-content/plugins/super-forms/uploads/php/files/24146a51f4b68fc857408bef49767a4b/biwomixineguworarora.pdfIn PDF document text
    • http://xn--dlek-5qa.com/admin/UserFiles/file/48359321517.pdfIn PDF document text