Malicious PDF — malware analysis report

Static analysis result for SHA-256 be1bbd4c03c0d2a2…

MALICIOUS

PDF

217.6 KB Created: 2021-06-27 12:35:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 622f6268c7458bf55c34a9a72bcb0c10 SHA-1: f1acd88c6473343811e12afee0c14aced44a3888 SHA-256: be1bbd4c03c0d2a2cb794186ebd1c041e83b05ca43c13ba84be24610b1833946
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file was detected as malicious by a ML classifier and ClamAV, indicating a high likelihood of malicious intent. It contains numerous links, with at least one pointing to a compromised WordPress upload storage, suggesting it's used to redirect users to malicious sites. The PDF structure and embedded links are consistent with phishing or malware distribution campaigns.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9852

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://biocoils.com/img/file/56213249436.pdf
    • https://www.chinacimctrailer.com/wp-content/plugins/super-forms/uploads/php/files/84369adc5b96a864c707b241de3303b2/40794660834.pdf
    • https://www.mclarenpress.com/wp-content/plugins/formcraft/file-upload/server/content/files/160755408403d8---81849562432.pdf
    • http://lowchens.org/userfiles/file/xazudotisadisoteni.pdf
    • http://saovietgroup.com/upload/FCK/file/8976830248.pdf
    • https://www.femregenx.co.za/wp-content/plugins/super-forms/uploads/php/files/4avr1m5aao7gse8l1aip3gld3k/30323172775.pdf
    • https://vieclamkinhdoanh247.com/upload/files/33502539093.pdf
    • https://www.sevgiliyevideo.net/wp-content/plugins/formcraft/file-upload/server/content/files/160b9ddf66655d---roxivuj.pdf
    • https://trucraftsmanship.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609ef5f341553---vusogozivujan.pdf
    • http://windcampus.com/wp-content/plugins/formcraft/file-upload/server/content/files/160791062cb97f---95504370420.pdf
    • http://www.fliesen-brill.de/wp-content/plugins/formcraft/file-upload/server/content/files/160ac032b41f13---17881368883.pdf
    • http://www.jimenez-casquet.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0fbba70635---62777637419.pdf
    • https://finestblogger.de/wp-content/plugins/super-forms/uploads/php/files/102vnpbqdj701nqr9v7s6eirab/85559744781.pdf
    • http://mijneigenlift.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160833b92c5f60---xuzaxodinorada.pdf
    • https://www.lokalesichtbarkeit.de/wp-content/plugins/super-forms/uploads/php/files/or3bfp5vhl5tjomvr5h7eaiadm/sureraxanenejosepedo.pdf
    • http://akcjonariusz.com/UserFiles/file/rovusonatenufoda.pdf
    • https://rrvchefs.com/wp-content/plugins/super-forms/uploads/php/files/fe8ef0ccc2bb5614fba949ddd6398764/lejokipesasowexaf.pdf
    • http://bochosushi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a02a3d368d9---rikagopewilisotetobefew.pdf
    • https://dfa-finanz.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aba49d5f68f---wiroximokudusumonobuzava.pdf
    • https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075f62fbdf04.pdf
    • http://tovicetour.com/FileData/ckfinder/files/20210605_7A9CE91D482776A5.pdf
    • https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/a31896641ea15b6b99ca742ea01f63b2/toragesugib.pdf
    • http://www.rlktechniek.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607d523f808b9---bavusug.pdf
    • http://primaneighbors.com/userimages/kopud.pdf
    • http://budaikepkeret.hu/uploads/file/72018799531.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=weeding+and+hoeing
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002f588.bin
67c468b54952b6feec4a01e5b7f910cee260337bee022591cb2bd221d4c64a6c
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F588 19816 bytes
font_01_sfnt_off00032a2f.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x32A2F 16792 bytes
font_02_sfnt_off00034246.bin
53e4d675bea9881ba5f658966ea29fffbd6e96c798ed3c3e463e57cdb036abcc
pdf-font-stream PDF embedded font (sfnt) at offset 0x34246 10108 bytes