Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3d6381ffb896e88…

MALICIOUS

PDF

169.0 KB Created: 2021-06-19 02:00:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 006d1eb61e8da1eaed0b5babd3687674 SHA-1: 2be6a569dd904455d2d98ee2a7699ee51335b153 SHA-256: c3d6381ffb896e880e7bde4fba310d1f8ccb0a06e37ac66e95959a8db51684b4
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded URLs, many pointing to compromised WordPress upload directories and disposable hosting, suggesting a link farm designed to redirect users to malicious content. The ML classifier also flagged this PDF as malicious with high confidence. The presence of multiple external URIs and links to potentially compromised sites indicates an attempt to lead the user to a malicious download or phishing page.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8964

Heuristics 6

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://inwebjor.ru/uplcv?utm_term=d%2526d+5e+dragonborn+sorcerer
    • http://granite1962.com/clients/869125/File/64758228938.pdf
    • https://autosaloncenter.com/uploads/file/pisajakixakudowosorebop.pdf
    • http://www.annaleehuber.com/content_files/file/jugewofapemoguto.pdf
    • https://capitaleny.com/wp-content/plugins/super-forms/uploads/php/files/565971ca4e1215e9182fd0f7ab8e01ac/wifaluvibenelewufapa.pdf
    • https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d6665b250f---kinujo.pdf
    • http://orderbestwings.com/uploads/files/69969917861.pdf
    • http://aelma.com/sites/default/userfiles/file/44558077040.pdf
    • http://visualpaint.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f4d52580ce---32074289983.pdf
    • http://mega.kz/media/upload/files/31244358215.pdf
    • https://propbrains.com/wp-content/plugins/super-forms/uploads/php/files/kbn6fbsg85ltq7irha5eaf9d22/wisarawopinere.pdf
    • http://files.ibiza-ferien.de/file/paduzozuwunajetadewixomi.pdf
    • https://cristiandellavedova.com/wp-content/plugins/super-forms/uploads/php/files/lrdepqcvpcbr5n3no5vv41ulg4/92236776621.pdf
    • http://hornets88.com/clients/56662/File/85876868819.pdf
    • https://insights3.com/wp-content/plugins/super-forms/uploads/php/files/7cb5e680a2191b27342bafc968b88ef0/zatusugomixejesoju.pdf
    • http://coumert.com/images/file/91637562780.pdf
    • https://festival-bg.com/media/ckuploads/files/lelexaso.pdf
    • http://for-rent-leuven.com/wp-content/plugins/formcraft/file-upload/server/content/files/16071eaa7d14ce---tatejoxez.pdf
    • http://79.170.40.182/boothtastic.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085e98aaabe8---vafogimosepipo.pdf
    • https://adm.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/0ba319129898e69b0b2efa777bb85cfa/88803792932.pdf
    • http://www.opentle.org
    • http://fedorahosted.org/lohit
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • http://www.daltonmaag.com/
    • http://www.indictrans.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://www.gnu.org/licenses/gpl.html
    • http://scripts.sil.org/OFL
    • https://gitlab.com/smc/meera/blob/master/COPYING
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • http://sinhala.sourceforge.net/
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITS
    • http://www.gnu.org/licenses/gpl-2.0.html
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHong
    • http://www.geocities.com/dnhhng
    • http://scripts.sil.org
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 18

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_010_off0001f1e5.bin
0848011c5bc734ee643db138d530f95bec50730ff15d4ad7ce2dc2994fec1047
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1F1E5 19380 bytes
font_00_sfnt_off0000ec55.bin
488ffee5e9c33bcc1f3f00aec749f35977d0cdd209ffadaee35194d66ecc177d
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC55 6148 bytes
font_01_sfnt_off0000fc36.bin
a3092163937b5c2949d1986ae69da3692f5096c98e1e1b86342fcf3090b92528
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC36 3612 bytes
font_02_sfnt_off00010a4b.bin
83e86e1b9f4a933a99eafaf4ac44543770a090311534d9e4ac6eabe207e81af2
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A4B 18952 bytes
font_03_sfnt_off00013fc1.bin
10b1e8ca5c1ffd40509c37c8d23269801adcfe34a1607cb54df6c3846a3e687a
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FC1 3484 bytes
font_04_sfnt_off00014b2d.bin
5fd53e2058c4f5d98b70161d670f1e42036942552fef68ac845a5e47e2d7f715
pdf-font-stream PDF embedded font (sfnt) at offset 0x14B2D 2604 bytes
font_05_sfnt_off00015645.bin
b5c6b6e0c9ada0bf1c6b02372d38a6194b0fc304f51b15768a03b7bd417def48
pdf-font-stream PDF embedded font (sfnt) at offset 0x15645 3048 bytes
font_06_sfnt_off00016252.bin
ff8289fcab20b7b81f5dc7c47458689637225d7099c48932a46d6898d6123f6c
pdf-font-stream PDF embedded font (sfnt) at offset 0x16252 2656 bytes
font_07_sfnt_off00016d2f.bin
98f616fae5e1bb9d8ae005e6b4fe81ae83f046cb525d1227f361f417600e392b
pdf-font-stream PDF embedded font (sfnt) at offset 0x16D2F 47624 bytes
font_09_sfnt_off00021319.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x21319 4324 bytes
font_10_sfnt_off0002211e.bin
2a2f73c0ee504ae8509221dab9a50e72e6c400a18e3952d3eee660ba18a0c3b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x2211E 4140 bytes
font_11_sfnt_off00022e0e.bin
5b8e8035f8940535bfb5f3d78de7d5c45dbc51c905faa5d9788b8fc152e96872
pdf-font-stream PDF embedded font (sfnt) at offset 0x22E0E 3840 bytes
font_12_sfnt_off00023c26.bin
5fc9e2cd4e7ad04544edda2023dd698132b65daf167a61e09de9fd8de66d8b52
pdf-font-stream PDF embedded font (sfnt) at offset 0x23C26 2108 bytes
font_13_sfnt_off000245fe.bin
ff18c81e36cb9b15efdbce47b580caf324ee17e344593362339bc7644b00bcc1
pdf-font-stream PDF embedded font (sfnt) at offset 0x245FE 4544 bytes
font_14_sfnt_off0002540e.bin
87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284
pdf-font-stream PDF embedded font (sfnt) at offset 0x2540E 4336 bytes
font_15_sfnt_off000261b8.bin
5cc8f364962355ae475115db944fd7a4d20f38d86c7f7c448382747ab212ad85
pdf-font-stream PDF embedded font (sfnt) at offset 0x261B8 4216 bytes
font_16_sfnt_off00026f74.bin
2e595141cfc5a730015d867094056734cd151f5b215480bba884d522f17c5808
pdf-font-stream PDF embedded font (sfnt) at offset 0x26F74 7916 bytes
font_17_sfnt_off00028409.bin
18b250f24057ce91e4a59b25c1eec79fa8b4d7e2cb9f6c0de02c7e032a072fd4
pdf-font-stream PDF embedded font (sfnt) at offset 0x28409 2328 bytes