Malicious PDF — malware analysis report

Static analysis result for SHA-256 b48cd113e3294463…

MALICIOUS

PDF

83.7 KB Created: 2021-09-01 12:26:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-05
MD5: a51d3e0c54c7ddac6f6aedc3663a724f SHA-1: 191ef321e1d818e0716300d168151cbb06ed1732 SHA-256: b48cd113e3294463aec38b8c364c1a286b27ad362a830c077feb5ec0247d85ef
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded links, many pointing to compromised WordPress sites and disposable hosting, indicating a link farm designed to distribute malicious content. The ClamAV detection and ML classifier strongly suggest a phishing or trojan payload. Although no scripts were directly extracted, the nature of the embedded links and the PDF structure suggest an attempt to redirect the user to a malicious site, likely for phishing or to download a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9974

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cottingham-group.com/cufiles/files/1426990128.pdf In PDF document text
    • https://cualuoihoanmy.com/uploads/userfiles/file/wigebom.pdfIn PDF document text
    • http://bezpieczna-strefa.pl/wp-content/plugins/super-forms/uploads/php/files/1bb976fe9ab0b72d53f7a2cd23454c29/medipesimaken.pdfIn PDF document text
    • https://fmpride.com/wp-content/plugins/super-forms/uploads/php/files/80919a60b3a0d282043736fe791d92c5/barixeg.pdfIn PDF document text
    • https://thejasmineway.net/wp-content/plugins/super-forms/uploads/php/files/dha7l6vc91ies2duv7b0hv6lph/52752108765.pdfIn PDF document text
    • http://ypcalumni.com/clients/2/24/24042806289e0d450134266962f0a0d8/File/dikaka.pdfIn PDF document text
    • http://2020kellyfamilyreunion.com/clients/1/1c/1c0e63424c3b5e20a3d858f77c59864f/File/32031106104.pdfIn PDF document text
    • https://bonekarusa.com/contents/files/labapotoduvepofokusa.pdfIn PDF document text
    • https://kindeeyudee.com/ck_files/files/41992944234.pdfIn PDF document text
    • http://arci-mp.fr/admin/File/17994928084.pdfIn PDF document text
    • http://xn--b1adbbbaeqjtsflbfms0e.xn--p1ai/pict/file/vadadugifew.pdfIn PDF document text
    • http://giasudaihocsupham.com/Images_upload/files/97185386399.pdfIn PDF document text
    • http://ecandrychow.pl/Image/files/68719406167.pdfIn PDF document text
    • https://vcubusinesssolutions.com/userfiles/file/boboge.pdfIn PDF document text
    • http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160a20b6f33ec5---numuvuwamazozodadovil.pdfIn PDF document text
    • https://www.dishdivvy.com/wp-content/plugins/super-forms/uploads/php/files/45e085f6a372b7ec7646460fd108217f/gapogavopemovu.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d09afd60748---75838502221.pdfIn PDF document text
    • http://tpokebar.com/uploads/files/53332235149.pdfIn PDF document text
    • http://bajajsports.com/userfiles/file/rurizizaxigekomuras.pdfIn PDF document text
    • http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/qiq98nasip19affajlb3dsq5d1/44416499627.pdfIn PDF document text
    • http://hzyixiangchem.com/upload/files/buguwoliwifeteb.pdfIn PDF document text
    • https://www.northernillumination.com/wp-content/plugins/super-forms/uploads/php/files/b4494eef71078e48f143e7287ca76c8d/rilufafumudalura.pdfIn PDF document text
    • https://tekartltd.com/upload/files/50386350130.pdfIn PDF document text
    • http://tatugigo.com/ckfinder/userfiles/files/66271397575.pdfIn PDF document text
    • https://encouragingmath.com/wp-content/plugins/super-forms/uploads/php/files/985a930c6e0d7e67e9a2a2d424cdd1a3/42768276797.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/PmAiG5ZyT-k/uplcv?utm_term=new+heavenly+sword+and+dragon+sabre+2019PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e076.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE076 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0000f88d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF88D 11180 bytes
SHA-256: 0936dd903f62c60aca12fd9c1467dc899e32515603717084ad07d2ffc1de6d79
font_02_sfnt_off00011291.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11291 17944 bytes
SHA-256: c5c70d304c43e7872ac0bd9aa7f128d347650c79e884b07b074b4015b3bd88e2