Malicious PDF — malware analysis report

Static analysis result for SHA-256 c9b8ed500fb32089…

MALICIOUS

PDF

96.0 KB Created: 2021-09-07 16:00:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-14
MD5: 3de7e45d70a060d4af47707a5dd26fcf SHA-1: c545169ef2443aea094723a110484cb491d27ec8 SHA-256: c9b8ed500fb32089e8969a078fedadda05040df4c8c6da67ead8f2a71862d607
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, with ClamAV identifying it as Pdf.Phishing.Trojan. The numerous embedded URLs point to compromised WordPress uploads and disposable hosting, indicating a link farm designed to redirect users to malicious content. The presence of PDF_URI and PDF_SEO_DISPOSABLE_LINK_FARM heuristics strongly suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8324

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://laborke.ru/uplcv?utm_term=libro+comportamiento+del+consumidor+hoyer+pdf PDF link annotation
    • http://eot.mn/uploads/userfiles/files/gizivikepima.pdfIn PDF document text
    • http://china-zzld.com/uploadfile/file///2021060216555423.pdfIn PDF document text
    • https://sharjahcements.com/images/bulk_images/files/kiweforatalonobuk.pdfIn PDF document text
    • https://boyanbolyarski.com/userfiles/file/xajeputolaf.pdfIn PDF document text
    • https://ludifrance.fr/userfiles/file/64426469713.pdfIn PDF document text
    • http://hyeminshop.com/DATA/files/14706190804.pdfIn PDF document text
    • http://xn--b1ahhafccpgkb2bxo.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/d27806f91a3b0ddac3d517622f206659/38542091569.pdfIn PDF document text
    • https://emilline.dk/ckfinder/userfiles/files/fidurugobumidu.pdfIn PDF document text
    • http://chapraptti.org/userfiles/file/77815231020.pdfIn PDF document text
    • http://scandirent-new.ru/uploads/assets/file/dinotofamibeleregeri.pdfIn PDF document text
    • http://xn----9sbbnbtte4cyg.xn--p1ai/ckfinder/userfiles/files/resab.pdfIn PDF document text
    • http://honmamon-s.com/img_seminar/userfiles//file/dawaf.pdfIn PDF document text
    • https://rosedreamholidayhomes.com/ckfinder/userfiles/files/53683989590.pdfIn PDF document text
    • http://cutskytools.com/d/files/11297077647.pdfIn PDF document text
    • https://verandapattaya.com/userfiles/files/72756382288.pdfIn PDF document text
    • https://landatur.com/files/galeria/files/wavuwagufofutur.pdfIn PDF document text
    • https://realestateconnect.us/wp-content/plugins/super-forms/uploads/php/files/t2c1rllfahgb8l1g8fdba2a1d4/76781045667.pdfIn PDF document text
    • https://mastirz.com/userfiles/files/30440133791.pdfIn PDF document text
    • http://mcalesterhighschool1960sreunion.com/clients/e/e6/e641a1dc2b4fc8b0483efb779338bfbd/File/92227539998.pdfIn PDF document text
    • http://buyyoutubelikes.com/ci/userfiles/files/77977899348.pdfIn PDF document text
    • https://hogies.com/includes/template/uploads/file/91242871548.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16119e340553bf---67607253971.pdfIn PDF document text
    • http://dopuskvsro.ru/UserFiles/37068501124.pdfIn PDF document text