Malicious PDF — malware analysis report

Static analysis result for SHA-256 c190fd295acfb5f4…

MALICIOUS

PDF

63.7 KB Created: 2021-08-05 12:59:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-11
MD5: 6b24673e44dd1f0fb555afce567e4696 SHA-1: fc861f96c063e24b5ddfaffbdd43d5739cf9cfa2 SHA-256: c190fd295acfb5f422719a547a16df8a72016c94a6a1a619d0697d0724159d3a
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was identified as malicious by ClamAV and an ML classifier, indicating a phishing or malware distribution attempt. It contains numerous links, many pointing to compromised WordPress upload directories, suggesting it functions as a link farm to redirect users to malicious sites. The presence of external URIs and link farm heuristics strongly supports this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6736

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.karavanlakesfet.com/wp-content/plugins/super-forms/uploads/php/files/4315c157d25359b3f6e5fc4a8e567f21/38195212740.pdf In PDF document text
    • https://expungemyrecordnj.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cc97dbc1154---rilekigilip.pdfIn PDF document text
    • https://petroblend.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075596ea005a---74395844625.pdfIn PDF document text
    • http://maslatalaia.com/userfiles/file/pizenuwifafenabeletarota.pdfIn PDF document text
    • http://janjoling.com/public/ckfinder/userfiles/files/kubivizetonegopudovatina.pdfIn PDF document text
    • http://christopherdallo.com/file/werifidamijabonevotuti.pdfIn PDF document text
    • https://greshamgilessalon.com/wp-content/plugins/super-forms/uploads/php/files/619df23a52c61585729e8fe75abab35a/vozatafodibufomoxorin.pdfIn PDF document text
    • https://www.duffylighting.com/wp-content/plugins/super-forms/uploads/php/files/280ce79bf51a9e9f6369a851ad163fbb/sojafukabofuw.pdfIn PDF document text
    • http://timebymtm.com/upload/files/84321940113.pdfIn PDF document text
    • https://www.piramideidiomas.com/ckfinder/userfiles/files/pudanatinub.pdfIn PDF document text
    • http://www.segurosfacility.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160d4ce4264289---mefurumedifolibulad.pdfIn PDF document text
    • http://gardatrans.com/content/Files/18578617362.pdfIn PDF document text
    • https://sevsport.info/wp-content/plugins/super-forms/uploads/php/files/e2bf009d479d6b54e956b991400f0627/92260813741.pdfIn PDF document text
    • https://naseeha.org/wp-content/plugins/super-forms/uploads/php/files/5eee77344d8cc1a6fd7bfa4038630d5c/8154334314.pdfIn PDF document text
    • https://snabavto.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a87c4332b57---28493188068.pdfIn PDF document text
    • http://www.gonouvellezelande.com/files/59437964555.pdfIn PDF document text
    • http://osullivanspressurewashing.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e8347b8224---3037330626.pdfIn PDF document text
    • http://www.ebsjosepirosamaria.com/wp-content/plugins/formcraft/file-upload/server/content/files/1610000561b5f7---gilamamabiso.pdfIn PDF document text
    • http://www.halpellet.hu/userfiles/files/61222764377.pdfIn PDF document text
    • https://makemycake.gr/wp-content/plugins/super-forms/uploads/php/files/nkcves3m7r9udsdrm3evm7je85/xetitonif.pdfIn PDF document text
    • https://legacyltg.com/wp-content/plugins/super-forms/uploads/php/files/b47edc58b30d1abb316ee84379d420c0/sepilumumen.pdfIn PDF document text
    • https://atx-stroy.ru/wp-content/plugins/super-forms/uploads/php/files/dd4063a98e03bfafcf494aa324c1f16c/vigixabaxowoguju.pdfIn PDF document text
    • http://lirealestatelitigator.com/wp-content/plugins/super-forms/uploads/php/files/48b8ed477a4abb49922cdaabc0e7b50e/nepolegedewogaxima.pdfIn PDF document text
    • http://www.deco-interieure.com/userfiles/file/babafozefovaxagide.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/fzgW7-mxBc0/uplcv?utm_term=carrie+2013+full+movie+in+hindi+dubbed+watch+onlinePDF link annotation
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e7a5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE7A5 11464 bytes
SHA-256: b4929e112ff68385c514eb76eb3ec33d1fbd386ca0c56a1ad6e1a6c86947a364