Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae2feedaa25cd5d0…

MALICIOUS

PDF

98.2 KB Created: 2021-07-09 05:26:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 7a2e6e01a69a0b4140792ea8fce34b02 SHA-1: e9b64e0cc42bfbd1e3ddf82c1922e3c7e84bd496 SHA-256: ae2feedaa25cd5d0872c7925aa581e3a348338e8608dff564c7935ccfeddf256
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm pointing to multiple compromised WordPress sites, specifically targeting their file upload functionalities. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or distributing further malware. Although no scripts were directly extracted, the PDF structure and embedded links suggest it's designed to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9781

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://multiseal.com.ph/wp-content/plugins/formcraft/file-upload/server/content/files/1606ccb34783ea---naradukeletumaresalajar.pdf
    • https://www.abaco-engineering.it/wp-content/plugins/formcraft/file-upload/server/content/files/1609ceff195513---59387388561.pdf
    • https://yuktiedu.com/wp-content/plugins/super-forms/uploads/php/files/aeed5effa61bd5c56533c75e55f36d92/wiwiw.pdf
    • https://campermagazine.tv/public/file/revetokajukapoxufela.pdf
    • http://huijingweb.com/upload_fck/file/2021-7-9/20210709054638893075.pdf
    • http://www.adanakursmerkezi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16073c06357439---wejakixuxukulasifebi.pdf
    • http://amadpich.com/userfiles/file/tigok.pdf
    • https://photographerin.agency/wp-content/plugins/super-forms/uploads/php/files/nf8tk2og3v6e2irh7e6suf2ms2/mobobojonebofujilu.pdf
    • http://peaceinsrilanka.lk/userfiles/file/bamigut.pdf
    • http://www.ellisrasbetonwerke.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160ac24fdec22a---37108116335.pdf
    • http://www.roosprommenschenckelfoundation.nl/ckfinder/files/files/kotebironaji.pdf
    • http://crmrealty360degree.in/userfiles/file/78689117874.pdf
    • http://phillipsbricksalumni.com/clients/56168/File/32972688192.pdf
    • https://stegopackaging.com/wp-content/plugins/super-forms/uploads/php/files/4s3fdg0qccvm6uisq5mvtmrrbl/nibunipapajekapapanuwole.pdf
    • http://rittenhousereunion.com/clients/a/ad/ad7d26974070b67854a29702aed78614/File/suledi.pdf
    • https://cfi-registration.org/buzzboxgift/img/userfiles/files/gagezakerak.pdf
    • https://smilepath.com.au/wp-content/plugins/super-forms/uploads/php/files/9673c1e9eee28451d0c6862da118993e/52138532519.pdf
    • https://mobistore.co.nz/wp-content/plugins/super-forms/uploads/php/files/abc2d6ebbb478035dc15d4fc0fb49fe7/21694897292.pdf
    • https://mfdesign.hu/files/file/dixofobonam.pdf
    • http://iideree.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608aa7900bdd4---42521230961.pdf
    • https://k-kompany.ru/wp-content/plugins/super-forms/uploads/php/files/7b2ed54d9781e86c71b7888070535d9e/23340658651.pdf
    • https://mytopics.it/uploads/file/64520039183.pdf
    • http://cnkls.com/userfiles/file/1624943929.pdf
    • https://feedproxy.google.com/~r/skout/mBVl/~3/1xuhb7AK25c/uplcv?utm_term=vocabulary+for+ielts+pauline+cullen+audio+download
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e596.bin
4fc2f5d91862bae782a8ecf1a8bde0b08bfdb3a5e93f9f829e7feb3c29fb31c2
pdf-font-stream PDF embedded font (sfnt) at offset 0xE596 11024 bytes
font_01_sfnt_off0000ff2b.bin
cf35f12662b5a50f69ad9da21d5d64998dcfc6364e4eec28c5036aeec2056a42
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF2B 3072 bytes
font_02_sfnt_off00010bb9.bin
f1a740745e4a0f39666a726c564c1cf8c875c3138cda8677ee751beef139568e
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BB9 16372 bytes
font_03_sfnt_off00012222.bin
c021e35343c87c922fa7d53fa085c9f19c9a3827ff269b1fe34cf81a8dddb266
pdf-font-stream PDF embedded font (sfnt) at offset 0x12222 27600 bytes
font_04_sfnt_off00015fdd.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x15FDD 16792 bytes