Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5934d9bc1075947…

MALICIOUS

PDF

54.0 KB Created: 2021-06-21 06:02:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: 035ce251572c64b017dbf817d0683d12 SHA-1: decae4d3235c48210cffa4bb9c69dba80f52725b SHA-256: a5934d9bc1075947e56ef470d0e49ebb735fdd53736ce0991492060041f4b2c5
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document is identified as malicious by ClamAV and an ML classifier, indicating it is likely a phishing or trojan delivery mechanism. It contains numerous links to compromised WordPress upload directories, suggesting it is part of a link farm designed to redirect users to malicious content. The document body, though heavily obfuscated, contains metadata related to 'wkhtmltopdf' and a calculator lure, reinforcing the phishing pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6232

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://oniceh.ru/uplcv?utm_term=finding+missing+angles+in+triangles+calculator PDF link annotation
    • https://flycam.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160c7254f45540---58900969449.pdfIn PDF document text
    • http://www.rolstoellift.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c6933997ebe---rigozabazibuwedosubib.pdfIn PDF document text
    • https://messianic.live/wp-content/plugins/super-forms/uploads/php/files/f87dd6cc550d559577d4e895341f4378/4236268575.pdfIn PDF document text
    • http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/3rrglrr4kgak98blaouoebo6d6/94734536029.pdfIn PDF document text
    • https://hcs1000.org/wp-content/plugins/super-forms/uploads/php/files/1f45064855a4cf2a697e18aa803c482a/riwerifipasaxa.pdfIn PDF document text
    • http://deckdreams.ca/clients/3/34/34055ef41782f8f15ebf372c1e39ecad/File/voligemonoduliduxukivuv.pdfIn PDF document text
    • https://seitonsolutions.com/ci/files/fowapufitonenedu.pdfIn PDF document text
    • https://bettenbaehren.de/wp-content/plugins/formcraft/file-upload/server/content/files/16087ca6f630c2---98610314991.pdfIn PDF document text
    • https://bayardplaza.co.uk/wp-content/plugins/super-forms/uploads/php/files/nsvbbuv56vt49eqsfqdvmojsit/39757209497.pdfIn PDF document text
    • http://jointrilogy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d4d57845bf---29938669086.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b6e2c5dadf1---pijuz.pdfIn PDF document text
    • http://drvision.org/wp-content/plugins/formcraft/file-upload/server/content/files/160b25563274f7---mozasivi.pdfIn PDF document text
    • http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/160722d9157f62---giledumalowidoxi.pdfIn PDF document text
    • https://jdbailbonds.com/wp-content/plugins/super-forms/uploads/php/files/0885d0ab6fbda6dd2403f1d41cee3ab2/78341007647.pdfIn PDF document text
    • http://hanleyresources.com/images/megalakofopekigeji.pdfIn PDF document text