Malicious PDF — malware analysis report

Static analysis result for SHA-256 b15d3444597255ef…

MALICIOUS

PDF

80.1 KB Created: 2021-06-28 21:18:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 97b7a65a67b812b0997cbe5818b35d9f SHA-1: b64c3ece1838868266a9a3f97737f5d497c9df73 SHA-256: b15d3444597255ef123fb6fa87af4a48dc234aa8075c03f6ca900e55c3c17cf9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a PDF file detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains numerous URLs pointing to compromised WordPress sites, suggesting a link farm designed to redirect users to malicious content. The presence of embedded URLs and the nature of the heuristics strongly suggest this PDF is part of a phishing campaign, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9953

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://archism.ru/uplcv?utm_term=fanfares+and+flowers
    • https://visaonline-vn.com/wp-content/plugins/super-forms/uploads/php/files/dtooocafm4c1do8sg0p6d8nvo5/mokaleleki.pdf
    • http://lalitas-thaimassage-spa.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607635bacb787---dibatufavefezelizewa.pdf
    • http://evabody.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1608bf543be270---vasejazav.pdf
    • http://www.nandomoraes.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160ab936dd833c---95175017984.pdf
    • https://chicagoportablexray.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a05f8a654d0---4974304934.pdf
    • http://flygarfield.net/userfiles/file/daxiwakoloxeratemilagu.pdf
    • http://sibinetweek.ru/userfiles/file/nijinegataduzorisafobi.pdf
    • http://evabody.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160902acb266fd---kobukekodilor.pdf
    • http://gorisum.net/fckeditor/upload_file/file/depinimawidu.pdf
    • http://www.zywawiara.pl/pliki/ponavuzepetudoredezoripib.pdf
    • https://holzhaus-suedtirol.it/wp-content/plugins/formcraft/file-upload/server/content/files/16073aa55e9f70---madaragun.pdf
    • http://training-solutions.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1606f6508f3755---8814871612.pdf
    • https://www.temsilcisitesi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a82bb3580bd---natajepojusoxelisimejamar.pdf
    • https://cafesca.info/ckfinder/userfiles/files/ruregogetogakuvukune.pdf
    • https://olgunbey.com/upload/ckfinder/files/tasoxibajawemixoxod.pdf
    • https://srmhomes.com/images/bulk_images/files/puguferutololarawo.pdf
    • https://www.vibrationmonitoring.asia/wp-content/plugins/formcraft/file-upload/server/content/files/16090ab38aaeb5---zenusomijumiruw.pdf
    • http://permianhighschool1970.com/clients/e/ef/efee9fcbc667252fc4b649c8163d3733/File/64910746585.pdf
    • http://janatalnajaf.com/basefile/janatalnajafcom/files/45769285322.pdf
    • http://banlinhkienlaptop.com/userfiles/file/radivuvadezo.pdf
    • http://www.sunarmisir.com.tr/wp-content/plugins/super-forms/uploads/php/files/iu93pru91f9nrcrt4p24o7fon0/ludalativ.pdf
    • https://xn--80aaaglcftt5alesfkk7f.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/142955e8fc0067455b3e72257568c3b1/furizijidupupurilexima.pdf
    • https://realestateconnect.biz/wp-content/plugins/super-forms/uploads/php/files/1gljsceekkgt05c0326fgj6so2/zugapizu.pdf
    • https://sunarchegypt.com/userfiles/file/fuxazepivetif.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d429.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD429 16792 bytes
font_01_sfnt_off0000ec3b.bin
092dedf3730fa775b2dd66c148fdb01ca75b6a941d628f87b11e51cc01851c5b
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC3B 18480 bytes
font_02_sfnt_off00011c8e.bin
09247a38296eb2060f3286aadcf747fa684259928fd3964107c61ae2f6a3b499
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C8E 10220 bytes