Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb9d70b037a4fbb3…

MALICIOUS

PDF

81.0 KB Created: 2021-06-25 23:18:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: b97c2985119979701347313db1e48b15 SHA-1: 046aac152891491438bb2eda495d51f74df7adef SHA-256: bb9d70b037a4fbb33bb00fd3c482dc1ff7e571931550a5f433b087660b79950b
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains a link farm pointing to numerous compromised WordPress sites, likely serving as a distribution point for further malicious content. The presence of embedded URLs and the nature of the heuristics suggest an attempt to trick users into downloading additional malicious files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9949

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.bridalchapel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607c7a3e744ea---71722612454.pdf
    • https://wentworthre.com/wp-content/plugins/super-forms/uploads/php/files/643fa48ca332c0f6dbffa3c6b31ba7be/59368056588.pdf
    • http://anhuishangbiao.com/upload_fck/file/2021-6-15/20210615002412641352.pdf
    • https://otartufo.com/ckfinder/tartufofiles/files/74638470800.pdf
    • https://eventaipei.com/upload/files/kebuxagafabugejixa.pdf
    • https://allmassage.net/upload/file/20210611022200.pdf
    • http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160985f2e95492---94589927285.pdf
    • http://queuemanagementsystems.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609af22808c1d---zegutane.pdf
    • http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/tdhb9dj9u06gg0ks10vs2jr370/4732463331.pdf
    • https://holzhaus-suedtirol.it/wp-content/plugins/formcraft/file-upload/server/content/files/160b3b35e1c34c---21356556994.pdf
    • https://pluckywize.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072d12ae3d79---8901144868.pdf
    • https://www.djluk.co.uk/wp-content/plugins/super-forms/uploads/php/files/ppoodg58ujv80d84c23lvttb2l/sebiwezitu.pdf
    • http://thunderstar.cn/userfiles/file/20210525235704332498340.pdf
    • http://nuraski.pl/wsg/userfiles/fesub.pdf
    • https://genesisbehaviorcenter.com/wp-content/plugins/super-forms/uploads/php/files/91819996ed3fb318df0b7d59c9d28a4f/morizuvelix.pdf
    • https://ski-experience-japan.com/images/blog//file/65346727399.pdf
    • http://nemdanangpho.com/uploads/2021-06-07/images/files/56079084126.pdf
    • http://accurateverdicts.com/wp-content/plugins/formcraft/file-upload/server/content/files/160869a9c1dda8---tokifuxofe.pdf
    • http://diagonal.org.ar/wp-content/plugins/formcraft/file-upload/server/content/files/160969a01a96f1---gevotere.pdf
    • http://eske.hu/wp-content/plugins/formcraft/file-upload/server/content/files/1606cd62d93ea3---56938621946.pdf
    • https://kakvkusno26.ru/wp-content/plugins/super-forms/uploads/php/files/78d7f778760589957bc74b9e2ee00c1e/fefiluxatugedumixerile.pdf
    • http://www.fliesen-brill.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608dc5cadfe2d---25956699421.pdf
    • https://classicandcamper.co.uk/wp-content/plugins/super-forms/uploads/php/files/qgn2urplmaoseitn9kamdg1dta/38173659791.pdf
    • https://artsketch.ru/wp-content/plugins/super-forms/uploads/php/files/2e9b4eb8c56c7fa01484d6c5decb4fc3/16260574605.pdf
    • https://www.thecandystoresudbury.com/wp-content/plugins/super-forms/uploads/php/files/jeuhn4pasggpas67rtdkskceqr/zagiwomusoregogemaveta.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=allstate+ready+mix
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d9e7.bin
6a5e430b0e6e3901208abaa71feac4481582a6515904f6ba058071f993f78f9a
pdf-font-stream PDF embedded font (sfnt) at offset 0xD9E7 17444 bytes
font_01_sfnt_off00010755.bin
03409a3ed24dbde74adc04cded7d5c43df93b10e9d29f0f3eee7756f1ca6dbf8
pdf-font-stream PDF embedded font (sfnt) at offset 0x10755 10384 bytes
font_02_sfnt_off00011ee5.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x11EE5 16792 bytes