Malicious PDF — malware analysis report

Static analysis result for SHA-256 954d015cbdcc5bae…

MALICIOUS

PDF

98.6 KB Created: 2021-07-04 02:57:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-16
MD5: fc2f1dc61d93a8eb3d75bdf9537e7524 SHA-1: f2304b0f68d23ffeb92237e3fe730c87928275b6 SHA-256: 954d015cbdcc5bae8f54deca904f26fa68a6fa0a53f410d80ade98bdd90c717f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.001 User Execution: Malicious Link

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The heuristics reveal it functions as a link farm, hosting numerous URLs on compromised WordPress sites, likely to facilitate phishing or malware distribution. Although no scripts were extracted, the structure and URL patterns are strongly indicative of a malicious document designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.medicalart.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1608fd812eb645---44781686816.pdf In PDF document text
    • https://www.frankreich-ferien.ch/wp-content/plugins/formcraft/file-upload/server/content/files/160bb779c9aa97---80638989186.pdfIn PDF document text
    • https://ag-concept.ru/wp-content/plugins/super-forms/uploads/php/files/39153b5c3112c68ef898dc538db782d1/kuninolifuk.pdfIn PDF document text
    • https://moto-trend.cz/public/files/fck/file/13511329193.pdfIn PDF document text
    • http://exlluprimebrochure.com/ckupload/files/zuvepuxajesorodum.pdfIn PDF document text
    • http://vmkmsz.hu/userfiles/file/vivadigubevevagiso.pdfIn PDF document text
    • https://www.picmephotoboothhire.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160b4783e935ed---pujagajam.pdfIn PDF document text
    • https://kachhiproperties.com/wp-content/plugins/super-forms/uploads/php/files/d4gd1dh7o3crr3u1ck2kebtmt4/xutewuletojekuvexe.pdfIn PDF document text
    • http://moyamoya.center/images/hand_uploaded/files/zokixebud.pdfIn PDF document text
    • https://jaunimodienos.lt/wp-content/plugins/super-forms/uploads/php/files/ko3uta1gjj5m5ug6ejombbol1t/40832867317.pdfIn PDF document text
    • https://lynnesnaturaltreats.com.au/wp-content/plugins/super-forms/uploads/php/files/0d6121e7b9897d0e1151e460b0204c9e/3339635686.pdfIn PDF document text
    • http://www.atrium-tuiles.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aa97235bb17---kepitageg.pdfIn PDF document text
    • https://wilsonbarrera.com/inicio/wp-content/plugins/formcraft/file-upload/server/content/files/160b00cd157bdf---74876752836.pdfIn PDF document text
    • https://aquariumfargo.com/wp-content/plugins/super-forms/uploads/php/files/c47f978cbcc887f38dc0d9159c31d3c0/tejujepaxozajexiwixinufe.pdfIn PDF document text
    • http://www.kreasoft.mx/wp-content/plugins/formcraft/file-upload/server/content/files/160a89a618a331---dirivepugigexesupuwopebel.pdfIn PDF document text
    • http://www.ddd-iasi.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1608d1ee769bc2---54911532468.pdfIn PDF document text
    • http://hkt-optics.com/hkt/images/userfiles/file/watafazawo.pdfIn PDF document text
    • https://www.dynasil.com/wp-content/plugins/super-forms/uploads/php/files/ee49a12dfdade065ad1d03792356d02a/73461579739.pdfIn PDF document text
    • http://www.jobsincrete.gr/images/_user_na/file/xowaziti.pdfIn PDF document text
    • http://www.asejnrtigers.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1607e24296da7b---98500316928.pdfIn PDF document text
    • https://miamivanservice.net/wp-content/plugins/formcraft/file-upload/server/content/files/1606c898ed2ae2---zajovuma.pdfIn PDF document text
    • https://beautifullifeuk.com/wp-content/plugins/super-forms/uploads/php/files/2819034bf465e404dc2f6ad89fe567a9/67969452469.pdfIn PDF document text
    • https://g-ortho.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160831746e3b63---71812234466.pdfIn PDF document text
    • http://mesotects.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094fa190d3e0---24629647001.pdfIn PDF document text
    • http://s8radziejowice-paszkow.pl/userfiles/file/69506715160.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=bauxite+specific+gravityPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000115c9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x115C9 10820 bytes
SHA-256: a90e4ba050a0c70c8f45b7d5962460417e95d6d93b21605266d138197a1de1f0
font_01_sfnt_off00012f01.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12F01 20440 bytes
SHA-256: dff613f5efbbbc5085aae91c410db6491899478ad2a7c7ff0a225eeef9c110d7
font_02_sfnt_off00016546.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16546 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1