Malicious PDF — malware analysis report

Static analysis result for SHA-256 9662727a611b9bfd…

MALICIOUS

PDF

80.8 KB Created: 2021-09-05 09:01:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-05
MD5: a7328ee816210d5f652a8929a2911735 SHA-1: dd1a224688a09361848d7aa80fae80f2970c96e8 SHA-256: 9662727a611b9bfdb0921c0d049b1befb2da09a7a9174ae27e76dbe2203decc2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links to external websites, many hosted on compromised CMS platforms, suggesting a phishing or malware distribution attempt. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9975

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://medvor.ru/uplcv?utm_term=tessellation+worksheets+to+colour PDF link annotation
    • https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/5e198e07368b2b7c80283c830eb935ee/zupunetexus.pdfIn PDF document text
    • https://abofahed.com/userfiles/file/9455321529.pdfIn PDF document text
    • https://alirezamirmohammadi.com/images/upload/files/xiforobekamuvilebusobiw.pdfIn PDF document text
    • https://www.intermediastudios.com.mx/wp-content/plugins/super-forms/uploads/php/files/c341fb100b0c0835e8add5158827ebf6/9086535818.pdfIn PDF document text
    • http://jiuxingchaoshi.com/uploads/file/071105126812.pdfIn PDF document text
    • http://k-sta.kr/FileData/ckfinder/files/20210810_E3DA06BC530233BF.pdfIn PDF document text
    • http://www.adanakursmerkezi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b4a35530ff---vovanolebizukowabivigix.pdfIn PDF document text
    • https://amagi.la/wp-content/plugins/formcraft/file-upload/server/content/files/1612e1fb3d2fa6---fiwenit.pdfIn PDF document text
    • http://apsons.eu/files/file/tupesixipulogorubilitu.pdfIn PDF document text
    • https://zweiund40.com/wp-content/plugins/super-forms/uploads/php/files/8ev21k9q1mf7bsvjfg6852hgiu/wadeburuximeguzebagev.pdfIn PDF document text
    • https://lisacutler.com/wp-content/plugins/formcraft/file-upload/server/content/files/1611e2c646efd9---takixixeredujexok.pdfIn PDF document text
    • http://schokobrunnen.com/idata/kuzefe.pdfIn PDF document text
    • https://digitaldaya.com/imagenes/file/58218866833.pdfIn PDF document text
    • http://www.amedna.com/userfiles/files/pipugavixiloxajideti.pdfIn PDF document text
    • http://ffarchitettura.it/userfiles/files/94162958982.pdfIn PDF document text
    • https://e-motorcycle.tw/upload/emotorcycle/files/18357535016.pdfIn PDF document text
    • http://ximangsongthao.com/app/webroot/uploads/files/79377940591.pdfIn PDF document text
    • https://crcnueva.naturasoftware.com/uploads/images/files/52560327944.pdfIn PDF document text
    • http://mulroyenvironmental.ie/userfiles/file/70738685234.pdfIn PDF document text
    • http://dom-nenilovo.ru/wp-content/plugins/super-forms/uploads/php/files/0ad99688effa9ea1c37d9b7ef306d996/kupep.pdfIn PDF document text
    • https://eletroluz-al.com/_IMG/img_internas/file/mepidafapasa.pdfIn PDF document text
    • https://cffcommunications.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/1606d331c1eb11---zamubarejide.pdfIn PDF document text
    • http://rorolaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/4890276056.pdfIn PDF document text
    • http://dailyliving.nl/ckfinder/userfiles/files/sidonipoka.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d680.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD680 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0000ee92.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE92 18020 bytes
SHA-256: 57db80701d5f08f39cd2223fb525302135426a07d01e8f7693bc5afc25d88b99
font_02_sfnt_off00011d55.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11D55 10568 bytes
SHA-256: c03942c8b335766843aa47d6d3188ae282643969328c2a151ea6496a9027c995