Malicious PDF — malware analysis report

Static analysis result for SHA-256 b80890187d23861f…

MALICIOUS

PDF

68.2 KB Created: 2021-05-15 09:36:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8b309f737ae5f701ace0445a3e5b7058 SHA-1: 4be5de7a7e060b9835bd370afe1a995d4caea893 SHA-256: b80890187d23861f14d9079ca8cfb359a51c33ab5a44630436e8b5ea2ed616dc
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing attempt. It contains numerous links to compromised WordPress sites, likely serving as a link farm to redirect users to malicious content. The document body, though heavily obfuscated, suggests a lure related to 'river flows piano sheet music free', aiming to trick users into visiting these compromised sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9711

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://afriqueitnews.com/wp-content/plugins/super-forms/uploads/php/files/4ab310a0099babc684b0431698cd9e07/80660175360.pdf
    • http://www.tif.cn/wp-content/plugins/super-forms/uploads/php/files/hm9jiqh1ml698p3psgqnksr29g/futawaja.pdf
    • https://suhrsmad.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1606f6a9ccd777---71071361873.pdf
    • https://amesmedicalservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/160721427acb33---29489529102.pdf
    • http://www.zulfugar.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16093c94e472b7---68623751135.pdf
    • https://www.citysecurity.org.uk/wp-content/plugins/super-forms/uploads/php/files/3h5p82ek6l857ijjgjtfcgjial/53563659943.pdf
    • http://vdgairconditioning.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16084253d7441f---63008566799.pdf
    • http://alpha-cp.com/userfiles/file/zefejutiwekusofukepudud.pdf
    • https://razdolle.by/wp-content/plugins/super-forms/uploads/php/files/gt7bou3rq0ov20k674uaipale7/34730119561.pdf
    • https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/160813e8f1408e---zedifewefokoxelonolutupo.pdf
    • https://414movement.com/wp-content/plugins/super-forms/uploads/php/files/18fe2debb1039d486847745cfe7ec8c4/81544884440.pdf
    • http://riskhedgetech.com/uploaded/file/9754004556093228eef5d2.pdf
    • http://vorne-sitzen.eu/pcms/content/file/25997949253.pdf
    • https://2greenchicks.com/wp-content/plugins/super-forms/uploads/php/files/4dece4c59a92d53283635dbe5d175d4d/dorezajikopujodusisilupem.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/skout/mBVl/~3/zMnd8XtcwSM/uplcv?utm_term=river+flows+piano+sheet+music+free
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dd35.bin
ea32d5020d71eba10de3fe7e33522f73a3d88a26e8a98d66345fcecf32674550
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD35 5412 bytes
font_01_sfnt_off0000ef94.bin
cf1972b32633f23392da004cdbe9b6c6248524e19ca0bc48dfd39dc30c83bc71
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF94 10624 bytes