Malicious PDF — malware analysis report

Static analysis result for SHA-256 b87a73ef8979facf…

MALICIOUS

PDF

84.1 KB Created: 2021-09-06 21:51:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-24
MD5: 2603c34b5ea6e679d21f6ca3034c588e SHA-1: 249222fd231e0f4a5bde6f5b4421a2e868831ec3 SHA-256: b87a73ef8979facf3a67beb9ae898aab8951777a00aaa17bbb08d681c334959a
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded URIs, many of which point to potentially compromised or disposable hosting domains, indicating a link farm designed to redirect users. The ML classifier strongly flagged this PDF as malicious, and the presence of multiple PDF_URI heuristics supports the conclusion that the document's primary purpose is to facilitate access to external malicious resources. The specific IP address http://211.129.1.225/system/ckfinder/userfiles/files/keluvanupukeg.pdf is a high-priority IOC.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9974

Heuristics 6

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://daimarconstrucciones.com/images/admin/file/80216220143.pdf In PDF document text
    • http://bindashnews.com/userfiles/file/61339004782.pdfIn PDF document text
    • http://sicilyontable.it/userfiles/files/derenolodel.pdfIn PDF document text
    • http://ferien-in-zahren.de/images/file/57331766442.pdfIn PDF document text
    • http://www.iqubz.com/wp-content/plugins/formcraft/file-upload/server/content/files/16098799291d0e---43658492347.pdfIn PDF document text
    • http://feriaalainversa.com/uploaded/files/51694586184.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c944fd2974c---zixijilimoba.pdfIn PDF document text
    • https://bushregenerators.info/userfiles/files/64680370801.pdfIn PDF document text
    • http://sintjorisparochie.nl/userfiles/file/depabevuvu.pdfIn PDF document text
    • https://aldea.work/wp-content/plugins/super-forms/uploads/php/files/73dd07d9f03fdc6783c2f6c6bc5ee01c/mosena.pdfIn PDF document text
    • http://bochosushi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160724750a1d8c---17959968629.pdfIn PDF document text
    • https://sandzak.best/wp-content/plugins/super-forms/uploads/php/files/51f9fbcbb9bd87485c6b0e8443ffa37f/kudofituxul.pdfIn PDF document text
    • http://faulkfamilync.com/clients/c/cc/ccb94402b1eed20a0583117be0c0b506/File/lewubiledusipinitisa.pdfIn PDF document text
    • http://esrafisek.com/images_upload/files/25900419885.pdfIn PDF document text
    • https://inverpalmas.com/aym_image/files/39542860956.pdfIn PDF document text
    • http://211.129.1.225/system/ckfinder/userfiles/files/keluvanupukeg.pdfPDF link annotation
    • http://akpanlawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/xonizapuxoka.pdfIn PDF document text
    • http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612ccdce5256e---rizegulolotibu.pdfIn PDF document text
    • https://arerp.kr/data/file///9313671758.pdfIn PDF document text
    • https://www.okcfarmersmarket.com/wp-content/plugins/super-forms/uploads/php/files/d1137d19f15e5153b8fc46fddbbd2d95/rexefonujezulipofafaror.pdfIn PDF document text
    • https://jclifeschools.org/wp-content/plugins/super-forms/uploads/php/files/8d9667cb1ddd54bc1f6de9505fdd6f64/91757606678.pdfIn PDF document text
    • http://grubstreet.ca/ckfinder/userfiles/files/77509565803.pdfIn PDF document text
    • https://afriqueitnews.com/wp-content/plugins/super-forms/uploads/php/files/eb9f4223a749bf0c1d0915fce338ba49/5307062980.pdfIn PDF document text
    • http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/160956eca2a8ea---gotazekufumofus.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=vrio+model+pdfPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8b6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE8B6 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off000100c8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x100C8 16936 bytes
SHA-256: 920a654b9035d535698e6d41ffcc1c03a1d37be0e5cd042126f7d720f863675d
font_02_sfnt_off00012c79.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12C79 10096 bytes
SHA-256: ae7887ec4d387e6ec2eea64762003a072c0b33056c7a63067248a704bcd15700