Malicious PDF — malware analysis report

Static analysis result for SHA-256 d32b193e163066ae…

MALICIOUS

PDF

126.8 KB Created: 2021-07-05 21:38:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-09-14
MD5: 7a99f048c93a986fac6f8de9dfe8f478 SHA-1: e10f577123a54c475ecfa1eb90bfa9161546599e SHA-256: d32b193e163066aeddb0afa391f612ae1561bc58bd12406bd23d3417cd3e3726
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm with numerous URLs, many hosted on compromised WordPress sites, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. The file's structure and URL patterns are consistent with a malicious PDF designed to lure users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9957

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://longarmquiltacademy.net/fckeditor/userfiles/file/vubudenedopivupoleseve.pdf In PDF document text
    • https://torrentclub.vip/wp-content/plugins/super-forms/uploads/php/files/55po3b5640ft60nc5r8c2ov9rs/bejuzumufiki.pdfIn PDF document text
    • https://www.okcfarmersmarket.com/wp-content/plugins/super-forms/uploads/php/files/07e479d9be3d93f36fe5689b5e172cd0/20623060083.pdfIn PDF document text
    • https://rebel-guitars.com/wp-content/plugins/super-forms/uploads/php/files/6a49c272bb6ab13d415200a15674fc8b/26886023016.pdfIn PDF document text
    • http://ptairsupply.com/userfiles/file/77792762397.pdfIn PDF document text
    • https://forcechicago.com/wp-content/plugins/super-forms/uploads/php/files/6e6c237fd21e609dc4a61674eba46cdb/14438795349.pdfIn PDF document text
    • https://suksesunited.com/contents//files/vegezebesanufudalis.pdfIn PDF document text
    • http://www.expo-hotel.com/english/wp-content/plugins/formcraft/file-upload/server/content/files/1606d56bc36992---jotupedavowogoj.pdfIn PDF document text
    • https://jjmassociates.com/wp-content/plugins/super-forms/uploads/php/files/07a24edc2615bd0e4ed6c7b60f181006/gapexopobiloz.pdfIn PDF document text
    • https://www.onestopnaturalstore.ca/wp-content/plugins/super-forms/uploads/php/files/eaps9oi25j9588d4uecra90i9d/fokuwujixigofarerokol.pdfIn PDF document text
    • https://apparel.allianceflooring.net/wp-content/plugins/super-forms/uploads/php/files/10e5ad3548c5af9dd7374b2ac1ac6e17/44770468686.pdfIn PDF document text
    • https://www.perfumista.co.uk/wp-content/plugins/super-forms/uploads/php/files/9a85a56080ccba381bac2cfaa5a78a12/91120401038.pdfIn PDF document text
    • https://blueridgelightingandcontrols.com/wp-content/plugins/super-forms/uploads/php/files/aba8e06508fb192a7bab23ee9bdcbede/sevuzowuluxe.pdfIn PDF document text
    • http://www.hypnotiseur.com/wp-content/plugins/formcraft/file-upload/server/content/files/16090fe276b455---46736533716.pdfIn PDF document text
    • http://ivepe-elearning.gr/assets/UserFiles/mainHome/file/lilowu.pdfIn PDF document text
    • http://kompletucetnictvi.cz/files/file/benuna.pdfIn PDF document text
    • https://tecsal.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160a61b3cb6880---mibelogukododefaxovag.pdfIn PDF document text
    • http://phillipwhiting.com/wp-content/plugins/formcraft/file-upload/server/content/files/16092f1bc6557f---77263096455.pdfIn PDF document text
    • https://winston-woodward.com/wp-content/plugins/super-forms/uploads/php/files/26307e7cef921e2b15ce434c6b608841/89224722222.pdfIn PDF document text
    • https://elitteaccesorios.com/wp-content/plugins/super-forms/uploads/php/files/ndb1di6lhmi13sqeak00br7jq1/zupewobopal.pdfIn PDF document text
    • http://caacoding.net/wp-content/plugins/formcraft/file-upload/server/content/files/160ac7de1c328b---23819021288.pdfIn PDF document text
    • https://sheenabusesandcoaches.com/userfiles/file/68798342062.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/Om9ozkHLxGw/uplcv?utm_term=ind+as+109PDF link annotation
    • http://lovewhereyoulv.wpengine.com/wp-content/plugins/super-forms/uploads/php/files/7ff71ba10fc5bfebc1cc3eada2f00a86/kufuzeniz.pdfIn PDF document text
    • http://lovewhereyoulv.wpengine.com/wp-content/plugins/super-forms/uploads/php/files/e712b96e6bcb2328a9def3e2a0f965d8/gapanixaxejotufabep.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019544.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19544 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0001ad56.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1AD56 16468 bytes
SHA-256: ccb4d441894c3cc8ad925981203ae519e77b7e6706c9e4be076c8b6cea8d742d
font_02_sfnt_off0001d805.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D805 9948 bytes
SHA-256: 51008f8a4347dfe29e20dae9d31da2491325b264787227c59438990b2c87a0c3