Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1c5e0ed75718ad2…

MALICIOUS

PDF

74.6 KB Created: 2021-09-05 04:52:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-24
MD5: 37468b82191fbab8a2afefe54ac3a884 SHA-1: e6bf5be0252042707ce2570868e15fa5071b0400 SHA-256: b1c5e0ed75718ad2b53a29158d2c04a436bc141d1423c2d81772228f04fe0e71
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by ML classifiers and ClamAV as malicious. It contains a large number of embedded URLs, many of which point to compromised websites or disposable hosting, indicating a link farm designed to distribute malicious content or phish users. The presence of numerous external URIs and link farm heuristics strongly suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dbcasagayathottam.org/assets/uploads/cms_images/files/98334835019.pdf In PDF document text
    • https://thuaphatlaihoanghuy.com/uploads/files/zagoni.pdfIn PDF document text
    • https://motodubai.com/uploaded_images/files/sunetilijulesijomijep.pdfIn PDF document text
    • https://zmiz.hr/userfiles/file/vufixugexuxinesame.pdfIn PDF document text
    • http://vivo-mebel.ru/upload/file/zojisuxulufolebogomijuje.pdfIn PDF document text
    • http://progfin.pl/userfiles/file/pafupejewufoxixaga.pdfIn PDF document text
    • http://855solution.com/htdocs/cljr/data/files/norabonur.pdfIn PDF document text
    • http://wo-kop.pl/userfiles/file/13877244587.pdfIn PDF document text
    • https://polinagerz.ru/wp-content/plugins/super-forms/uploads/php/files/r1tqc1q62ll4u79hjll82qus64/51896690837.pdfIn PDF document text
    • http://asu.com.vn/wp-content/plugins/super-forms/uploads/php/files/4n2c8kh21a3us313uu6504r15k/zolodejuni.pdfIn PDF document text
    • http://prosquash.by/data/67187187904.pdfIn PDF document text
    • https://europartner2.pl/uploads/posuxumotululuzaxetaw.pdfIn PDF document text
    • https://www.plsok.com/wp-content/plugins/super-forms/uploads/php/files/2d1c093822c45652eb3fb5424d97bb9d/32142007310.pdfIn PDF document text
    • http://amblesidewindermere.ca/fckuploads/images/file/xajekudef.pdfIn PDF document text
    • http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/5hrva5577m3dae6cg126bg00l3/puzemegatotuzemuvukerinej.pdfIn PDF document text
    • https://reifenscho.de/wp-content/plugins/formcraft/file-upload/server/content/files/160f88704df630---52175938857.pdfIn PDF document text
    • http://soldresold.com/Shradhdha-Mehra/soldresold/final/ckeditorimage/files/lidaxiduwigelusiwavitos.pdfIn PDF document text
    • http://www.jhannahs.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d642832239f---86647272903.pdfIn PDF document text
    • https://namastehealth.in/wp-content/plugins/super-forms/uploads/php/files/rdp9k55n5h6e3fd6j32ln5mq98/43480728403.pdfIn PDF document text
    • http://nhagiatxanh.com/public/default/ckeditor/files/11220309248.pdfIn PDF document text
    • http://www.radioemka.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074b7635f209---54203976748.pdfIn PDF document text
    • https://realimpacto.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1610e19c37438e---xinuvil.pdfIn PDF document text
    • https://mls.lighting/wp-content/plugins/super-forms/uploads/php/files/a623d63441f62a811c79813d09c95641/97028491351.pdfIn PDF document text
    • http://hanabi-la.com/uploads/files/7109577042.pdfIn PDF document text
    • https://carpanea.it/wp-content/plugins/super-forms/uploads/php/files/185c849b5eb5dd321b4495e6109014c7/zizujiripokeru.pdfIn PDF document text
    • http://training-solutions.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160d235e6b7145---dixeperuvidej.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=salvadora+persica+pdfPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bb57.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBB57 10552 bytes
SHA-256: 947c964bf0534f339b30dc10dd0954e81d9e11efe3dd1bcb00f6fe04991ff86c
font_01_sfnt_off0000d373.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD373 18648 bytes
SHA-256: d77ac927f44825885b7a77c8c4407beaa56a1031af3f7b593c09a028e6f67b9a
font_02_sfnt_off00010497.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10497 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1