Malicious PDF — malware analysis report

Static analysis result for SHA-256 acd5fc5cb40840bc…

MALICIOUS

PDF

73.3 KB Created: 2021-04-27 23:20:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-17
MD5: 573e3964ad6f889f5854e1b6e2030ad6 SHA-1: e030ae73b3a1badc28dba0e524b0948cb12aa5ae SHA-256: acd5fc5cb40840bc245ffe8fed1ccb43e9c0e57985022cd9ad995c6a726d24f8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document exhibits characteristics of a phishing or malware distribution lure, as indicated by the ClamAV detection and ML classifier flagging it as malicious. It contains a link farm pointing to multiple compromised WordPress sites, suggesting an attempt to host malicious content or redirect users to phishing pages. The document's title, "Clue junior detective sheets," is likely a social engineering tactic to entice users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.sarajevo-inn-grunewald.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ca76f0accd---ritixawagamogila.pdf In PDF document text
    • https://donnasalon.ru/wp-content/plugins/super-forms/uploads/php/files/6326a65c3c40195b57b222a4300a5784/92684905830.pdfIn PDF document text
    • http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/160783530eea45---pojarowuwefodegupiwegax.pdfIn PDF document text
    • https://www.wikiwebagency.it/wp-content/plugins/super-forms/uploads/php/files/cd9c1ee8c2a4f600bcd5d186a89be2c9/38900711476.pdfIn PDF document text
    • https://taxiparga.com/wp-content/plugins/super-forms/uploads/php/files/e9694b9b3cca64309abef2516a3af957/lisemimig.pdfIn PDF document text
    • https://jjmassociates.com/wp-content/plugins/super-forms/uploads/php/files/fdfc260c64dbdb56a23f9334ec46e80e/lesakisilugusimet.pdfIn PDF document text
    • https://www.pferde-fuer-unsere-kinder.de/wp-content/plugins/formcraft/file-upload/server/content/files/16080cf580e449---1952612851.pdfIn PDF document text
    • https://fjordancv.info/wp-content/plugins/super-forms/uploads/php/files/70cd43912406ea0e4bde66377333e537/figugebumuzojevizutug.pdfIn PDF document text
    • http://ttlengenharia.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16087b3dcdb699---29541383326.pdfIn PDF document text
    • https://cullinanconstruction.com/wp-content/plugins/super-forms/uploads/php/files/t8190ve7fnj8prluccsmpivi58/55035240412.pdfIn PDF document text
    • https://gz-topstar.com/wp-content/plugins/super-forms/uploads/php/files/2760ae1b41846ea3dd4f8f5f0a0e45b0/pobifomavobupetijijomejim.pdfIn PDF document text
    • https://totalyoumovement.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083151353dbb---99562101915.pdfIn PDF document text
    • http://asesoriagarpe.com/wp-content/plugins/formcraft/file-upload/server/content/files/160856ef229db2---65766064038.pdfIn PDF document text
    • https://xn--1--8kcai1ck2bs.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/86ed73ef259b490179cc55d7a7e0024c/fatoxubavog.pdfIn PDF document text
    • http://www.rec39.ru/wp-content/plugins/super-forms/uploads/php/files/734441795cb5c2c746945861a7bd397d/bupikutulibasiw.pdfIn PDF document text
    • http://www.norestim.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16081ebfe130fc---23651826675.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/FevRqgeaUVY/uplcv?utm_term=clue+junior+detective+sheetsPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d023.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD023 4856 bytes
SHA-256: f98328c876bf5994c758172d493ae694db1c5faa26a323748b26b523048bca70
font_01_sfnt_off0000e0a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE0A8 10656 bytes
SHA-256: fc1780b3553e4b6d9882a15ebc41b2b65069178ad37469ebaec16611733cea35
font_02_sfnt_off0001053e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1053E 16228 bytes
SHA-256: 12025b4d7aa04fb8f69941e4d866040d4f6caaea9902973765e58cdc1b50fbbe