Malicious PDF — malware analysis report

Static analysis result for SHA-256 a38db3d870a1d6f7…

MALICIOUS

PDF

310.8 KB Created: 2021-07-03 08:41:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 7d64114098aae778dce34ac507970561 SHA-1: a21a080309b36d3fae5867173504b0d41713d46e SHA-256: a38db3d870a1d6f7c8384a3b2e65895ce6995aeda2a9c6f2d3414e11a7fcd469
166 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The file was detected as malicious by ClamAV and an ML classifier, exhibiting characteristics of an advance-fee scam. It contains numerous links to external PDFs hosted on compromised WordPress sites, suggesting a phishing or malware distribution attempt. The document body was unreadable, but the heuristics strongly indicate a lure for financial fraud.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9888

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://synerhu.ru/uplcv?utm_term=words+with+j+and+k+in+them
    • https://immobilgold.com/file/78323106979.pdf
    • http://slowjamsundays.com/wp-content/plugins/formcraft/file-upload/server/content/files/16096ab50341d2---xesutowepupezulezumedu.pdf
    • http://mirembeestate.co.ug/wp-content/plugins/formcraft/file-upload/server/content/files/1607a65fdac86f---38003699132.pdf
    • https://www.glasswindowequipment.com/wp-content/plugins/super-forms/uploads/php/files/dcab66a6f212420baf10be6bc0e834f1/37454123623.pdf
    • https://www.lesson-online.org/wp-content/plugins/super-forms/uploads/php/files/7ruu7jqh2808lskbojo171gg66/naralutetifogax.pdf
    • https://www.acptechnologies.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bfd4471eebe---52733490131.pdf
    • http://cropscipublisher.com/files/upfiles/file/rujezevovozibeguzas.pdf
    • https://www.pennlighting.com/wp-content/plugins/super-forms/uploads/php/files/10201296b1d602f09bd1ba8b41f43f7e/82570226049.pdf
    • https://apexforestservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160724b0b895ca---76312683094.pdf
    • http://nuovartea.eu/userfiles/files/vonobarenuvu.pdf
    • https://avis-medical.ma/wp-content/plugins/super-forms/uploads/php/files/fd38b9732192856111eacb38042ca039/besewokizeloj.pdf
    • https://www.brunosistemi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a2fffef6a7---676774391.pdf
    • http://odesignlab.ru/admin/ckfinder/userfiles/files/30253148797.pdf
    • https://blackknowledge.com/wp-content/plugins/super-forms/uploads/php/files/4c2293f54232c6456efbba58bc56cd5b/31579110267.pdf
    • https://atlasautoglass.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c8c5340840a---21858066745.pdf
    • https://www.cir.cloud/wp-content/plugins/formcraft/file-upload/server/content/files/160778fab6b1d9---komuzopigozebokurajezad.pdf
    • http://festivaldeliteraturadepereira.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e2a9c7bf38---3067628260.pdf
    • https://simondaulte.com/ckfinder/userfiles/files/loximipowotinoretij.pdf
    • https://shining4u.com/wp-content/plugins/super-forms/uploads/php/files/589c884960c678a487e36368b06efeec/jisorebazos.pdf
    • https://www.sidertest.it/wp-content/plugins/formcraft/file-upload/server/content/files/16073913d74d98---77061905783.pdf
    • https://comesa.com.pe/wp-content/plugins/super-forms/uploads/php/files/k9e5i79ja69jbi68bsa4n8j1s5/xagewubixudavebagowajem.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00045411.bin
700da9b01466270df35104b7f033f8ad45877573a5a64e52c5f18ddc209c4bd1
pdf-font-stream PDF embedded font (sfnt) at offset 0x45411 10768 bytes
font_01_sfnt_off00046ca7.bin
0bbdee2383a32df4d1e553917e0521842d865c14213c322349bbea9e9b840831
pdf-font-stream PDF embedded font (sfnt) at offset 0x46CA7 18644 bytes
font_02_sfnt_off00049db0.bin
60e59e701608a08463d5b80eeb63078ed3bb5b9c42262fbabdebabc3f6b258bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x49DB0 16084 bytes
font_03_sfnt_off0004b2da.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B2DA 16792 bytes