Malicious PDF — malware analysis report

Static analysis result for SHA-256 980c607af859c671…

MALICIOUS

PDF

140.2 KB Created: 2021-05-23 12:51:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7dbb00647d457aa7331efb737fc94188 SHA-1: a4c46e71e7146cbd5abe94e0c9f4baaae5da332e SHA-256: 980c607af859c671ca34c4dd53ed0fa52b5d2c871014458b2e0f0eb3909e335a
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier. It contains numerous links pointing to compromised WordPress sites and disposable hosting, suggesting a link farm or phishing lure. The embedded URLs, such as 'https://infrive.ru/uplcv?utm_term=el+moasser+science+prep+1+guide+answer+of+el-moasser+math', likely serve as redirects to malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9609

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://infrive.ru/uplcv?utm_term=el+moasser+science+prep+1+guide+answer+of+el-moasser+math
    • https://signaturetowerpune.com/wp-content/plugins/super-forms/uploads/php/files/tid6q4fq7a9bieam6r6o6m1p91/23689080292.pdf
    • http://www.marcado.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1608a641108495---40391199679.pdf
    • https://alamansyria.com/userfiles/file/gemafa.pdf
    • https://coluer.ir/documents/file/nesonutup.pdf
    • http://associacaoguainumbi.org.br/wp/wp-content/plugins/formcraft/file-upload/server/content/files/1608365d73fbfe---gebafisebow.pdf
    • http://gtshotel.it/images/file/dokedekirofodiwexazur.pdf
    • https://edmaker.site/wp-content/plugins/super-forms/uploads/php/files/a1daad8274a6bd38a7d247ca02fb8b78/sejejituzobilaxub.pdf
    • https://aspaeng.com/files/image/files/bonemenagusexejusozefe.pdf
    • http://www.champcaregivers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f1c1240e79---85068748833.pdf
    • http://www.goataxiservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607747c22553c---roporuzekanozevemikiwer.pdf
    • https://erinmillssmilesdentistry.com/wp-content/plugins/super-forms/uploads/php/files/njd1mr0s2fs3a4mpar78p3gfc1/xijodasat.pdf
    • https://signaturetowerpune.com/wp-content/plugins/super-forms/uploads/php/files/7ru4nmff12fkuopisk0r9podr1/12894568564.pdf
    • https://mednet.mk/public_html/upload/userfiles/file/23975618958.pdf
    • https://inclinedigital.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072efed938c4---87411292631.pdf
    • https://purpleleafestatebuyers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c9de18addb---domopumafimimulew.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off000204ac.bin
fa7bc8bab12ea97790570b24750cf4242f8f1f99ffa227b5dd70b6f71445a072
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x204AC 28732 bytes
font_00_sfnt_off0001bfa9.bin
3780ef2e0227b26d78bd270286fc9a4d9b6a19a995e1ddc0908be137c6806ecf
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BFA9 5704 bytes
font_01_sfnt_off0001d302.bin
fd53433af4c174432a1d450130f62599d4ceada9c1e8c4d39d06530804c977f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D302 17112 bytes