Malicious PDF — malware analysis report

Static analysis result for SHA-256 cbd7a1190b5d1368…

MALICIOUS

PDF

348.1 KB Created: 2021-06-08 07:35:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-16
MD5: ae7b36736bd435b496918167e297e6fa SHA-1: 400c6f19e98387049ba5450e3ad1c7f880f35294 SHA-256: cbd7a1190b5d1368abfeae483018c8f4765ed867f2f31e14fd23f9a2bbbf9d01
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links to external resources, many of which point to compromised WordPress upload directories, suggesting a phishing or malware distribution attempt. The ClamAV detection as 'Pdf.Phishing.Trojan' further supports this assessment. The embedded URLs are likely used to redirect users to malicious content or download further stages of an attack.

Machine Learning

  • Nyx PDF Classifier clean score 0.1743

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://oniceh.ru/uplcv?utm_term=capital+letters+and+full+stops+worksheets+year+2 PDF link annotation
    • http://novussiteyonetimi.com/uploads/file/71718932902.pdfIn PDF document text
    • http://kingalbertltd.com/uploadedfiles/file/65233001299.pdfIn PDF document text
    • https://noks.cz/wp-content/plugins/formcraft/file-upload/server/content/files/16088564b532e4---lexewabikatopoxadakos.pdfIn PDF document text
    • http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/16085aa4459749---91398664739.pdfIn PDF document text
    • http://afgventuregroup.com/cfiles/file/jufupipuguminig.pdfIn PDF document text
    • http://baanpowertrain.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b3166f809ed---pizitomagoguzipow.pdfIn PDF document text
    • http://www.deadclan.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16083b18d22f02---21787893178.pdfIn PDF document text
    • https://www.heainc.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a9fc1ac54e7---fusijevodepu.pdfIn PDF document text
    • http://www.peopleoftheheath.com/wp-content/plugins/formcraft/file-upload/server/content/files/160887b2277c2e---rasuxojebirotidogop.pdfIn PDF document text
    • http://bestforfishing.com/wp-content/plugins/super-forms/uploads/php/files/8126f2170174f878a6cbb49d390f3700/kivabenuzifuzibejerites.pdfIn PDF document text
    • http://asesorialuishervas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a879a3b843---vivorenegubipigun.pdfIn PDF document text
    • https://40parables.com/wp-content/plugins/super-forms/uploads/php/files/7b28ca143dfd1e785941c3f920acecc0/55213748332.pdfIn PDF document text
    • https://cremeconferences.com/wp-content/plugins/super-forms/uploads/php/files/86632c759bad179a24fd803c7fcebf60/likazoga.pdfIn PDF document text
    • https://g-ortho.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16089f38ea631a---nemoxakebezewa.pdfIn PDF document text
    • http://www.consorcio.edu.pe/wp-content/plugins/formcraft/file-upload/server/content/files/1609877910cd0a---57016218940.pdfIn PDF document text
    • https://sitebyside.ru/wp-content/plugins/super-forms/uploads/php/files/9377cba2afc3620d59734dd238020585/29298854057.pdfIn PDF document text
    • https://provisionsinternational.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b6bebd2ffa6---kowikalifises.pdfIn PDF document text
    • http://uniondeautoescuelas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608511ea0814f---kafokimadub.pdfIn PDF document text
    • https://awlights.com/wp-content/plugins/super-forms/uploads/php/files/e5377f7673c8aef2cba611b17673faff/totimowatijemapegide.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHongIn PDF document text
    • http://www.geocities.com/dnhhngIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00042968.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x42968 6944 bytes
SHA-256: 5ad02f678b1627ce4e1e4875cf3fb220c649916d608939f168197669a5cbccca
font_01_sfnt_off00043aaa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43AAA 4200 bytes
SHA-256: 68f02f6f0e0cef56b3ede30c10181a0fcd095585cd80db30d7073bbd7a2e1583
font_02_sfnt_off0004499a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4499A 5424 bytes
SHA-256: a8d939ac776397ba425640414f38a299f2d85ff867e48bbcba8198d5feb83cdc
font_03_sfnt_off00045c1a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x45C1A 2136 bytes
SHA-256: a38695fe50f49a181ebe6a268040f1a5d6813482ede4d66ac55372f1be80d056
font_04_sfnt_off00046588.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x46588 3900 bytes
SHA-256: 0084d1c38370a04f0604fda7719fbcc9369ad7f75d17c9232cff10a8e807ab7c
font_05_sfnt_off000471ca.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x471CA 2316 bytes
SHA-256: 1bb1a7d313959ae56f5c302117ca941681a8819b56e265668678ebf834337a11
font_06_sfnt_off00047b10.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x47B10 4016 bytes
SHA-256: 1be335fa62576b69e8d48c65808748cd4167bbdee858e0cd9c9ab9ebd16048a6
font_07_sfnt_off00048731.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48731 1472 bytes
SHA-256: 9b22d44844c7583f5e8329bda20da6287bfd5fb1566fb37d3081dae9a862d2b9
font_08_sfnt_off00048f40.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48F40 5852 bytes
SHA-256: 4eb640e1f3fabda5edbf826275fd2b4fcf019bdef00b8e9104a7c9cd1fc42218
font_09_sfnt_off00049df9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x49DF9 1576 bytes
SHA-256: 961584759a5fa69f63651d56a66012d8bd6b737a50e556bbde468b4967770f65
font_10_sfnt_off0004a608.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4A608 24540 bytes
SHA-256: 2091b55022c96293dc33fb2355f098e36e8122feadae665fc76cb7a5e0fa3a21
font_11_sfnt_off0004e8f0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4E8F0 16868 bytes
SHA-256: 437e56fff63d24af86995253f15bed338b1dc7174498d8dd8c8ba566a287a32f
font_12_sfnt_off00050167.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x50167 24960 bytes
SHA-256: c14ca1efd79a1f988e90fd15111f6fb14611475a8b31c34797b361e09292999c
font_13_sfnt_off000543db.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x543DB 8876 bytes
SHA-256: 9142a80fd4ed9cc22404a14101f85b26d82b86f57731c3d1a34fcb9dc1d61634