Malicious PDF — malware analysis report

Static analysis result for SHA-256 b34502ef5f88a5d4…

MALICIOUS

PDF

95.6 KB Created: 2021-09-02 17:51:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: c8eefbcc98155774b4d21b72ac0a012b SHA-1: 0dbc9f6efb7941706cfbbc44d7f6784f0e78ff00 SHA-256: b34502ef5f88a5d4045a0c8a51678a720212f3bc376c74b0999c08ff55fd17a4
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The sample was identified as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. Heuristics indicate the PDF contains a link farm pointing to compromised CMS uploads and disposable hosting, suggesting a phishing or malware distribution lure. The embedded URLs are likely part of this scheme to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9889

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://boschvietnam.com/files/usersfiles/files/9556066440.pdf
    • http://msci.com.ng/wp-content/plugins/formcraft/file-upload/server/content/files/160e3b1afbc6e8---kowagudoxip.pdf
    • https://propbrains.com/wp-content/plugins/super-forms/uploads/php/files/i5pgmboa7v41cs85namcg7mm30/51469995483.pdf
    • http://www.asap-recruitment.net/upload/file/60738954111.pdf
    • https://transcendenceit.com/wp-content/plugins/super-forms/uploads/php/files/29d0a5ebfb9dfa11ff6ad94b8d155fd2/85806621058.pdf
    • http://from.ua/upload/articles/2021/06/11/files/rixusubuzomekolozumizona.pdf
    • https://rhdplumbing.com/wp-content/plugins/super-forms/uploads/php/files/0687b88fd9a0d3dcc67d55d11db0fde7/68247789868.pdf
    • https://mi-stores.com/basketballtotaal/images/editor/file/kuvizu.pdf
    • https://living-stone.lu/userfiles/files/dapije.pdf
    • http://hiddenforrest.net/clients/76790/File/wenuzusijolugunet.pdf
    • https://atphp.ch/userfiles/file/60463252872.pdf
    • http://www.siscard.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d72cecb41ee---xojokolela.pdf
    • http://ednak.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb42a476908---66555263129.pdf
    • https://prana.video/wp-content/plugins/super-forms/uploads/php/files/rties4nnrama8bfpckdcgcp361/530521419.pdf
    • http://nujhimachal.in/img/uploads/files/70870352557.pdf
    • https://laxmigrouppune.com/wp-content/plugins/super-forms/uploads/php/files/edfe81dff0a264da589977e3984cafc6/1537473178.pdf
    • https://bataretak.com/img/files/file/banimapipowosezowa.pdf
    • http://bwc.lt/i/sulixa.pdf
    • http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/160f9993441a5f---6110572293.pdf
    • http://valifyrepapillon.com/clients/6/68/68e1c6a84db99a04c21676ff826d6e37/File/32832463162.pdf
    • http://langeline.com/ckeditor/upload/files/88669025754.pdf
    • http://mko-yug.ru/wp-content/plugins/super-forms/uploads/php/files/a8bb02d236fa3b5b227bf177c5679c3b/deruzujafategevetoku.pdf
    • https://www.ccps.mx/wp-content/plugins/super-forms/uploads/php/files/7522233de70c2f8d49bcc3996ba81c3e/1123830542.pdf
    • http://xn--80an2aej.xn--p1ai/up/file/2348860456.pdf
    • http://www.circoloaletrium.it/wp-content/plugins/formcraft/file-upload/server/content/files/160ae75702228d---31359431594.pdf
    • https://taxfirma.com/userfiles/file/98994193664.pdf
    • http://ceresasrl.it/userfiles/files/borenewumajexademitene.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=nigerian+army+dssc+past+questions+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010b19.bin
219ad56796eb9b1fa9ef944cbfae9a785f9006c8391e24db8f728ff3c431835c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B19 11256 bytes
font_01_sfnt_off00012504.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12504 16792 bytes
font_02_sfnt_off00013d16.bin
4971417295944b23f90c34aa6eb367f8736b05a50f4869e690c3d8993f987426
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D16 19420 bytes