Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c45df4f9b037254…

MALICIOUS

PDF

88.1 KB Created: 2021-06-30 01:57:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: b5c8f3d5a2ea4dcdef0f5788da1087bf SHA-1: 3ee35e9b12f5f97d6b0da9ff6177a62f9374fad0 SHA-256: 9c45df4f9b03725429eb927da725244897332e7e9754cc2655d0f8440606b752
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links pointing to compromised WordPress sites and disposable hosting, indicating a link farm designed to redirect users to malicious content. ClamAV detection and ML classification confirm the malicious nature of the file. While no scripts were explicitly extracted, the heuristic firings strongly suggest the document's purpose is to facilitate access to external malicious resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://southtours.com/wp-content/plugins/super-forms/uploads/php/files/clmarmeflguc9mrvq2rs6pfh4i/44284006647.pdf
    • http://c2mag.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c2bb1775a9a---43214458069.pdf
    • http://feast.to/upd_file/wodalapasumekefu.pdf
    • https://bettenbaehren.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a555af8d360---33789797385.pdf
    • https://roweryelectra.eu/app/webroot/uploads/file/16240659215007.pdf
    • http://kystop.com/wp-content/plugins/super-forms/uploads/php/files/amn0o7cvk5ak6ajcir2vp75615/mawematizax.pdf
    • http://studiosimonepantaleo.it/userfiles/files/83547248287.pdf
    • http://kolaykanal.com/userfiles/files/rijodanopixun.pdf
    • http://eau-msu.ru/ckfinder/userfiles/files/26858286482.pdf
    • https://floridaholidayplanner.com/wp-content/plugins/super-forms/uploads/php/files/177e674c38bb99c463ca86855a0c893f/fosuzes.pdf
    • http://dossalas.com/wp-content/plugins/super-forms/uploads/php/files/3b84d35720c075f1241eded45c525e38/napedosevunabigozuvow.pdf
    • https://www.potterycommercials.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1607174d893e0a---47325802220.pdf
    • https://communeouchamps.fr/userfiles/file/41749966054.pdf
    • https://www.asahinafunnels.com/wp-content/plugins/super-forms/uploads/php/files/lfg3q1gf603pacvaqag7nub9n4/ramabexumibi.pdf
    • http://hasyo.net/files/file/joluxebegeveruxadez.pdf
    • http://officinedesign.it/userfiles/files/82915767974.pdf
    • https://fjordancv.info/wp-content/plugins/super-forms/uploads/php/files/57f5d2ba89c56eb4181538bfcd336fc6/18658590424.pdf
    • https://sipsib.ru/wp-content/plugins/super-forms/uploads/php/files/5745d976969ed9168cf2f6eed9581dd4/60780381714.pdf
    • https://envida-nieuws.nl/bsb_website/upload_fck/file/33008668533.pdf
    • http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/hsjqg0i4sk7gm0a37cugdinnj5/foxasilibob.pdf
    • https://mymovingestimate.com/wp-content/plugins/super-forms/uploads/php/files/19965f6424c897cd60469f4985158e0a/vazugibuwavugedeve.pdf
    • https://mamo-tato.ro/userfiles/file/ruzigapevotikekakabifevo.pdf
    • http://www.northeastmarquees.com/wp-content/plugins/super-forms/uploads/php/files/5ec602d6323dd469049909797505b8f3/81838198143.pdf
    • https://donnasalon.ru/wp-content/plugins/super-forms/uploads/php/files/effcac5a5ce3601ea421d18105facdaf/10826924527.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/FevRqgeaUVY/uplcv?utm_term=what+is+the+definition+of+affiant
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e0e1.bin
3c4f192e704dad93c48a10bd0cb014b19b40d86a524da1a1b4d4e2b781f39504
pdf-font-stream PDF embedded font (sfnt) at offset 0xE0E1 2992 bytes
font_01_sfnt_off0000ed35.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xED35 16792 bytes
font_02_sfnt_off0001054c.bin
07ee0ae179d5a4d5a886166081b368455b55eeefc00f2fbcbaaf53e7c44e8793
pdf-font-stream PDF embedded font (sfnt) at offset 0x1054C 10296 bytes
font_03_sfnt_off00011c77.bin
74f4101dc90dbbef2e5037aabecd4dd9dc0c1f3e144d412bc578bc63433c73fe
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C77 21596 bytes