Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa413e20b4e59afe…

MALICIOUS

PDF

109.0 KB Created: 2021-05-27 16:09:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: e725c96156835b29e7d405d09c9c951c SHA-1: 0f7b6ab69ff78e660ff26e500451271a06196cdc SHA-256: aa413e20b4e59afe71c1d0d5d9ec809ee80f39db9a667ba27c836450f2e69855
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing and trojan threat. It functions as a link farm, presenting numerous URLs that likely lead to further malicious content or downloads, disguised as movie download links. The presence of external URIs and compromised CMS upload links suggests an attempt to distribute malware or phish users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5890

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pixomot.ru/uplcv?utm_term=muhammad+the+messenger+of+god+2015+full+movie+download+in+urdu+480p PDF link annotation
    • https://takeorders.online/wp-content/plugins/super-forms/uploads/php/files/7quukr1m40hmga09rfb9r0siu1/75355229131.pdfIn PDF document text
    • http://www.doctor-carpet.com/wp-content/plugins/super-forms/uploads/php/files/3qdomahet9u7l4kci10t1l2936/fozorevokubebakoxulufe.pdfIn PDF document text
    • http://gostium.com/wp-content/plugins/formcraft/file-upload/server/content/files/160af93a5cb1f5---kobenawexesuwivup.pdfIn PDF document text
    • http://www.auditsi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608f8aa1aa44a---77158389525.pdfIn PDF document text
    • https://choiceenergynetwork.com/wp-content/plugins/super-forms/uploads/php/files/bd7705efb782236609de672868c49410/76481117565.pdfIn PDF document text
    • http://mujuerp.com/uploads/ckeditor/files/20210527185707.pdfIn PDF document text
    • http://polskienarty.pl/data/aktualnosci_imgs/file/fizevuzokopuje.pdfIn PDF document text
    • http://sotel-perm.ru/site/file/libikutixedani.pdfIn PDF document text
    • https://jennysbooks.com/wp-content/plugins/super-forms/uploads/php/files/d1956f177139f4ac83d1c73780a42a7f/28650590976.pdfIn PDF document text
    • https://lescourailleurs.com/upload/editor/file/54569048056.pdfIn PDF document text
    • https://www.basur-tedavisi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080ba4c676f8---57444722485.pdfIn PDF document text
    • https://www.chauffeur-prive-nice.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1606cb84105b64---sekatoniziwubow.pdfIn PDF document text
    • http://chocolatycakes.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072d58f29283---33108997036.pdfIn PDF document text
    • https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608b012e04320---putufowaxar.pdfIn PDF document text
    • https://pyhm.ca/wp-content/plugins/super-forms/uploads/php/files/m6mc3c0rou2i448108u405ut1n/21458183940.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000efdc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEFDC 7916 bytes
SHA-256: e679725072c74ab1de830ba6dd25101ec2f6d7be962e72d99a133184e56e62d0
font_01_sfnt_off0001043c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1043C 4032 bytes
SHA-256: 97c2b2e40c1385b4481fda1c9b3ae017bab0cd090847a61954886acf943b7a13
font_02_sfnt_off000112ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x112AD 6344 bytes
SHA-256: 415e16d37766eaaa484dd22b1cf268c4bf7587ae2dccfc29e1b0e33289181e5e
font_03_sfnt_off0001283e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1283E 2656 bytes
SHA-256: c206ac4eca120f096112d408dff6b33a2f721090936d80486df636e1cd240fde
font_04_sfnt_off00013342.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13342 4140 bytes
SHA-256: fbdd9df555c8710fa493947bde41d1b30e4b750f457ece442df516a7dd53c510
font_05_sfnt_off0001405e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1405E 3048 bytes
SHA-256: 4bb619f7e4c8d10c6650d66271e6db770d7def95493d885be3efe54e7c100c22
font_06_sfnt_off00014c6c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14C6C 2328 bytes
SHA-256: 3702365b3034b9d7945da23b991b5e2ac3f8bb06d1ba3be7e5ba1b5d8dd48c9f
font_07_sfnt_off00015725.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15725 2604 bytes
SHA-256: 7f3a1ef136f36ba68bc36e5bcd31de243dce7f4b60e01c4bc40f508baeb48ca0
font_08_sfnt_off00016200.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16200 3840 bytes
SHA-256: cca5298ad2e89ab0d41cc63a8205340d9321530172a8d5dda1c28d17fa56adaa
font_09_sfnt_off0001700e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1700E 2108 bytes
SHA-256: e66bd646ff29f48b94a898642357a1d5295b77faffa0bd70eb77acb4aebc9a97
font_10_sfnt_off000179ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x179EC 4336 bytes
SHA-256: 87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284
font_11_sfnt_off0001878c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1878C 6148 bytes
SHA-256: 4910d0177da9f60ecc92c13a34fae8c5c38ffafb9e4e22a3c3fd987548b79157