Malicious PDF — malware analysis report

Static analysis result for SHA-256 947d42cfb81cecbf…

MALICIOUS

PDF

103.0 KB Created: 2021-06-26 01:36:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: d5ebafd8221a1fb963dae231f0bad22c SHA-1: 509ab94dba6ffe7d6d25f3ec21d8f0975e903308 SHA-256: 947d42cfb81cecbfaa118472a9a4ec94958dd0ff5ab9f536b54b13434d7f4dfb
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file contains numerous links pointing to compromised WordPress sites, suggesting an attempt to distribute malicious content. The presence of PDF_RANDOM_URL_LINK and PDF_SEO_DISPOSABLE_LINK_FARM heuristics indicates a pattern of hosting malicious files on potentially compromised or disposable infrastructure. The ClamAV detection as Pdf.Phishing.Trojan further supports the malicious nature of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9682

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://archism.ru/uplcv?utm_term=android+emulator+for+switch
    • http://www.fotografoeventimilano.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a4fa9eb89ad---xeguxakukolotalovulud.pdf
    • http://www.mvdisposal.com/wp-content/plugins/formcraft/file-upload/server/content/files/160712d231bfdd---nibipabokedifimamadaxab.pdf
    • https://www.phoenixdentalacademy.co.uk/wp-content/plugins/super-forms/uploads/php/files/9819303761ad90680368a0e08e49c093/lifinopisatoxisika.pdf
    • https://www.c2commercial.com/wp-content/plugins/super-forms/uploads/php/files/07d3aa9bee6451bf0fdc2c2f6eed1d40/51263672586.pdf
    • http://www.patricktennis.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16092c2284a5b1---varikejo.pdf
    • https://limmaginebistrot.com/file/zoduzo.pdf
    • http://www.naturapreserved.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e9f3eebe4f---mapimedegolela.pdf
    • http://countrysquirefoods.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607aa1c340dc8---bifewafisidexid.pdf
    • https://www.karenlovelee.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a0029b8029---movikokumunegisasizik.pdf
    • http://recruiters-zone.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a92a7e50c23---dutunabemidolalu.pdf
    • http://ed-web.cz/userfilesfile/powewixolunewopirogejusop.pdf
    • http://agataklimowska.pl/userfiles/file/medojadimodegenudipo.pdf
    • http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/9ssb5g2c12is8gl3p496qdjld7/6803096712.pdf
    • http://slowjamsundays.com/wp-content/plugins/formcraft/file-upload/server/content/files/160749705cacb2---99900859398.pdf
    • https://indacphuc.com/wp-content/plugins/super-forms/uploads/php/files/p17cql1e2ij1s6tu21qaggpo4g/dorunovejirizoropuwivikaf.pdf
    • http://alexanderkanevskyartgallery.com/clientMedia/file/88447339861.pdf
    • http://cageart.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160a2e5373a35d---leralabunuzevojefevi.pdf
    • http://sad-azov.ru/wp-content/plugins/super-forms/uploads/php/files/fb158127d2cb6f3baa054839504b34d8/womebajewagimev.pdf
    • https://impariant-club.ru/wp-content/plugins/super-forms/uploads/php/files/f972e126eb0c1970ea1db7e89bbcaef7/17445012066.pdf
    • http://www.louthadventures.ie/wp-content/plugins/formcraft/file-upload/server/content/files/160d3ad30cc8ed---zubipopetomej.pdf
    • https://www.hediyevideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609b423b0707a---70485714532.pdf
    • https://autoschiller.de/wp-content/plugins/formcraft/file-upload/server/content/files/160ae81f3c9b72---rinoluvilidegekufabaliden.pdf
    • https://www.harnoordesigns.com/wp-content/plugins/super-forms/uploads/php/files/epfs1f8ghainqtsof30rhb5i97/1496112263.pdf
    • https://www.revistadefiesta.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609322f32baa9---63020207554.pdf
    • http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160c79b3d9c0b3---1111800561.pdf
    • http://villaturri.it/wp-content/plugins/formcraft/file-upload/server/content/files/160867a9b566f2---xofiwisufufadikuxovuwuseb.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012513.bin
63026968a2e5110cb435f717a87fb9b3beb222302ab52389109d9548e04363d4
pdf-font-stream PDF embedded font (sfnt) at offset 0x12513 1772 bytes
font_01_sfnt_off00012d85.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12D85 16792 bytes
font_02_sfnt_off00014597.bin
09924c9297bf03cab544f91967b4b1993ba54cdbd2c511f4c38f3acc77dc0077
pdf-font-stream PDF embedded font (sfnt) at offset 0x14597 18000 bytes
font_03_sfnt_off000174b2.bin
343b78397f48ba8eeb630f541af5e47dbe0cb841992f6fe979da781801c4a915
pdf-font-stream PDF embedded font (sfnt) at offset 0x174B2 10908 bytes