Malicious PDF — malware analysis report

Static analysis result for SHA-256 d436f4fe7c390ce0…

MALICIOUS

PDF

87.5 KB Created: 2021-07-05 01:02:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 90012152245022f226dc0104a9cd881b SHA-1: ca6a54563e8608a7b5cd74c7d7dc1ac5cc5002f2 SHA-256: d436f4fe7c390ce05a90768b6152ac8f40940dc450811ce015861f2ed5eb155d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and an ML classifier indicated a high probability of maliciousness. The heuristics reveal it functions as a link farm, directing users to multiple compromised WordPress sites and potentially malicious domains like inwebjor.ru. These links likely serve as a distribution point for further malicious activity, such as phishing or malware downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9947

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://inwebjor.ru/uplcv?utm_term=multiples+of+6+7+and+8
    • http://quickfix-poland.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b03b47029f4---77646314961.pdf
    • https://www.sharpeningfactory.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0a6c624f78---62751999965.pdf
    • http://irmascaritasdejesus.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/16095e0e62371d---97903261193.pdf
    • https://profbuhotchet.ru/wp-content/plugins/super-forms/uploads/php/files/f878b03cf086008783bd8da17fa85699/mexemenixupikuzuwik.pdf
    • http://haiphongcontest.com/images/files/defogeleti.pdf
    • http://pogservice.ru/userfiles/file/divesatar.pdf
    • https://www.infratechgroep.nl/wp-content/plugins/super-forms/uploads/php/files/df796de5a341ab637d1abd8da0d6944f/94001079632.pdf
    • http://xn--80ackbssfuieecff0e8c.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/pv7evfsu48beetc7vaohq07765/27056947748.pdf
    • https://mls.lighting/wp-content/plugins/super-forms/uploads/php/files/77c09e5977f0e4254914d164ec9fa8e3/vojumatoniwakatibetasoxaf.pdf
    • https://www.enterpriselighting.com/wp-content/plugins/super-forms/uploads/php/files/5231058873a1037f255c9ae04416a493/58388944505.pdf
    • http://thm-holding.ru/wp-content/plugins/super-forms/uploads/php/files/67121f532680f3dabc77b3ab42e7d9f0/47111270920.pdf
    • http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609676a3a44e8---wokomuniperimunedowoxuse.pdf
    • https://camile.vn/wp-content/plugins/super-forms/uploads/php/files/v9to4nlh7kkiigbat4dlncelir/72563141130.pdf
    • https://nicemexico.net/wp-content/plugins/formcraft/file-upload/server/content/files/160aacae41c129---25192086821.pdf
    • http://www.nationaalgolfcongres.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16082117e9b4b5---42776599397.pdf
    • http://bertrandetgastineaudesigners.com/userfiles/file/45837236297.pdf
    • http://cwesp.biz/upload/file/41396909422.pdf
    • https://protechlighting.com/wp-content/plugins/super-forms/uploads/php/files/b4726921810927950f188e097c748896/xeliwixepokirumo.pdf
    • https://mannerfeltdesignteam.se/ckfinder/userfiles/files/ramefafadumaxidazobidorel.pdf
    • http://www.sg-callenberg.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609f2b1f81e2d---60594402269.pdf
    • http://www.mondzorgvesa-voorschoten.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1609a9ef515a20---54577853438.pdf
    • https://www.helpagesl.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608ecf70b58ed---zapanam.pdf
    • http://alimentosldm.com/userfiles/file/15826878878.pdf
    • https://ailani.org/wp-content/plugins/super-forms/uploads/php/files/27509a5c904bfd60254faf9c8c13852d/dureri.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f51c.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF51C 16792 bytes
font_01_sfnt_off00010d2e.bin
90a545da22e369c2a3d0a9f8139b595a27619c9665bfa36a8194376af75aa4c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D2E 16336 bytes
font_02_sfnt_off00013772.bin
c95b9953deea8e3a730252c2e01f6976f769f54ff66a38b7294dcb8138560591
pdf-font-stream PDF embedded font (sfnt) at offset 0x13772 10912 bytes