Malicious PDF — malware analysis report

Static analysis result for SHA-256 beeff694f70de78b…

MALICIOUS

PDF

93.8 KB Created: 2021-07-06 23:04:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-09-13
MD5: c694355dd8aa3d6da11786214bdb6fbd SHA-1: 4d885ecd73e715b5736d465ca585a23a0b92399d SHA-256: beeff694f70de78be91a82af4734134177754c8e3fce681c1547b755bed6cdba
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links pointing to compromised WordPress sites, suggesting a link farm designed to distribute malicious files. The presence of a direct IP address link and the ClamAV detection as 'Pdf.Phishing.Trojan' strongly indicate a phishing or scam attempt. While no scripts were directly extracted, the PDF structure and URI heuristics point towards an attempt to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9820

Heuristics 8

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.mclarenpress.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609318ff50b96---30004504779.pdf In PDF document text
    • https://wittnebel.dk/file/rewapepenir.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d2cad866f9c---kogovixurogedasaroru.pdfIn PDF document text
    • http://104.156.58.56/~web2inbox/wp-content/plugins/formcraft/file-upload/server/content/files/1607eabb4a3a6d---41656715271.pdfPDF link annotation
    • https://noble-worldwide.com/wp-content/plugins/super-forms/uploads/php/files/cfdbf0ab3d35841208a872611c13d44f/72167636527.pdfIn PDF document text
    • https://fotojursa.cz/userfiles/file/98834262620.pdfIn PDF document text
    • http://93564497.com/userfiles/57164763049.pdfIn PDF document text
    • https://www.audifonosdoshoydos.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a75bfac7fd---45131891080.pdfIn PDF document text
    • http://coinmarketsuite.com/ckfinder/userfiles/files/74105118268.pdfIn PDF document text
    • http://call.ae/wp-content/plugins/formcraft/file-upload/server/content/files/16075026830cfe---motes.pdfIn PDF document text
    • http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609863bad8feb---rujijokidunutiwobesa.pdfIn PDF document text
    • http://angerdress.store/ckfinder/userfiles/files/93421764287.pdfIn PDF document text
    • https://spacio.hk/attachment/file/53220782268.pdfIn PDF document text
    • https://avgdesign.com/userfiles/file/bogukakugemixitoliz.pdfIn PDF document text
    • https://betalinktech.com/blmedia/file/82022521830.pdfIn PDF document text
    • https://sumangold.net.vn/wp-content/plugins/super-forms/uploads/php/files/ct4iir5lf2ahmllss3p67d4u11/zarekovisezifu.pdfIn PDF document text
    • https://starbox.fr/img/files/wobibodajo.pdfIn PDF document text
    • http://compie.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160911a4452792---nutojadegaxaxeginulaz.pdfIn PDF document text
    • https://lightupalife.org.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1609ff39dd2203---tuwagopilojubitab.pdfIn PDF document text
    • https://www.18fire.com/wp-content/plugins/super-forms/uploads/php/files/5c63c30d018740b085ef3a226910b45e/xivumomup.pdfIn PDF document text
    • http://rolmech-strzelno.pl/Upload/file/gemomi.pdfIn PDF document text
    • http://www.onekaddy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606e6f485f87f---xurukatenowopelabutamef.pdfIn PDF document text
    • https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/3bpdt4k790ejoujo56iuv1531q/dazozikulogevumu.pdfIn PDF document text
    • https://wholisticvibrations.com/wp-content/plugins/super-forms/uploads/php/files/7ffa96e746b144f2fd5289d1abdec5e1/jamiwugo.pdfIn PDF document text
    • http://www.myhhsi.com/wp-content/plugins/super-forms/uploads/php/files/343e922419ddb972a1ee02c48aab6800/majelizi.pdfIn PDF document text
    • https://arhometutor.com/userfiles/file/40866275255.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/BkSY9tpko7c/uplcv?utm_term=interesting+questions+and+answers+in+interviewPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010a9a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A9A 17636 bytes
SHA-256: aa821a3da4a716954fca90f4dcc473d1404a030ac9ab9a5c2a2e3943b4418e6e
font_01_sfnt_off0001390f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1390F 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00015126.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15126 10724 bytes
SHA-256: 08451361b6e8105d70c6c5858e8aa1f8861542a23d673a9510453a0845092a6e