Malicious PDF — malware analysis report

Static analysis result for SHA-256 9cf07a296e274e3b…

MALICIOUS

PDF

63.6 KB Created: 2021-06-05 14:36:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 08c49e8924da3b56d91a0e3f33cf1ce8 SHA-1: 908dcf7aa084f359444849e268663c141014c114 SHA-256: 9cf07a296e274e3b143261c56200a81a9cbe87ec3b2ced11c582eb4817439c47
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links, many pointing to compromised WordPress sites and disposable hosting, suggesting a link farm or SEO poisoning attack. The presence of 'utm_term' in one URL indicates a potential phishing lure. ClamAV detection and ML classification confirm maliciousness, with the PDF being identified as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9954

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pistant.ru/uplcv?utm_term=car+parking+multiplayer+mod+apk+for+iphone
    • https://www.andyselfstorage.co.uk/wp-content/plugins/super-forms/uploads/php/files/9end5tuobor63pdoueakek58ps/wisetutuk.pdf
    • http://www.restorationservice.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160a8e3f29e04b---85522959273.pdf
    • https://securityguardsupply.org/php/uploads/file/dopavajexevu.pdf
    • https://deewo.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aa159e91057---zozadonenafeduzexabezaguj.pdf
    • http://albatrossmrn.com/konadnew/userfiles/file/42281990672.pdf
    • http://famcareconnect.org/wp-content/plugins/formcraft/file-upload/server/content/files/1606cdcf3cf9fd---xibuxezokezelifinozaj.pdf
    • https://sk-developers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f27ebeeab7---mujegixurijug.pdf
    • https://www.ideaklinik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1606d40d145c8c---30109754643.pdf
    • http://www.onekaddy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a9298da668---wotupopujedejipuxijalor.pdf
    • http://middlegeorgiacoinclub.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e127966378---23601561532.pdf
    • https://lakeshoresmilesdentistry.com/wp-content/plugins/super-forms/uploads/php/files/ng97jvkigjqsmvt1ijf3278a93/bozusulepafil.pdf
    • https://encoregallery.us/wp-content/plugins/super-forms/uploads/php/files/24a2e1f3612ec419a5caf71ebefa9c93/50457708061.pdf
    • http://steclotildehorton.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16085d8b840a02---16624589261.pdf
    • https://traveltokiev.com/wp-content/plugins/super-forms/uploads/php/files/6pvgupt7gs4jmnoaor1ecveqg5/95577489722.pdf
    • https://xn--64-mlcufjjaii0l.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/75ae8d3d39153c6f500473c42b0359a7/bijekarupadikez.pdf
    • https://www.properties-thassos.com/wp-content/plugins/super-forms/uploads/php/files/5m6es24lkbnqnmmlrvr2u4fv0j/rosona.pdf
    • https://sonarmusic.hu/up_image/file/39962175851.pdf
    • https://absolut-fit-and-dance.de/wp-content/plugins/super-forms/uploads/php/files/km9uj4knav3antvvvuumfpcj1r/sineveloki.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e0f5.bin
6a82873c7fcdd2459d3a578e5f9409fae8e772ec1a267d26f787f3d8f60faf33
pdf-font-stream PDF embedded font (sfnt) at offset 0xE0F5 5348 bytes