Malicious PDF — malware analysis report

Static analysis result for SHA-256 de1df212c2cf8f65…

MALICIOUS

PDF

98.9 KB Created: 2021-09-06 01:49:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-07
MD5: 886e6d2bef72d436204455b3194b4285 SHA-1: 9b54cb7062fab2ad8c3fe0663d477b709ab96a4b SHA-256: de1df212c2cf8f653bde27d5bf83ccb6e1b38d7b13de9cb912859632cf982df6
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. Numerous heuristics indicate the PDF is part of a link farm, directing users to compromised WordPress uploads and disposable hosting sites. The embedded URLs suggest the primary purpose is to redirect users to external, potentially malicious, content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9875

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://queure.ru/uplcv?utm_term=gulf+extrusion+aluminium+profiles+catalogue+pdf PDF link annotation
    • http://ttccid.com/userfiles/file/pekafurapurupuxodejotidu.pdfIn PDF document text
    • https://microfocus-realize2020mea.com/wp-content/plugins/super-forms/uploads/php/files/03b6db4aca16e05aa0f6709b7f4fd336/satiwewosatidobiwajo.pdfIn PDF document text
    • http://evansmedia.ca/userfiles/file/gitok.pdfIn PDF document text
    • http://mptech.vn/ckfinder/userfiles/files/badupezowepejovesan.pdfIn PDF document text
    • http://fastcredit.ge/userfiles/file/gimitududobof.pdfIn PDF document text
    • http://villa-carlshorst.de/sites/default/files/file/xabimogepozim.pdfIn PDF document text
    • http://kibbkw.com/uploads/file/ravudufupatalogawasutobuk.pdfIn PDF document text
    • https://yourtuscanyguide.com/wp-content/plugins/super-forms/uploads/php/files/8b3ni5kvocjfho753kth67juk7/19097202405.pdfIn PDF document text
    • http://someteme.com/archivos/_20210627045911.pdfIn PDF document text
    • http://vitalenzyme.com/uploads/fckupload/file/21173006322.pdfIn PDF document text
    • http://www.franklinwebdesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608825943dbb5---4193754702.pdfIn PDF document text
    • http://www.corazondelsol.es/ckfinder/userfiles/files/gabujir.pdfIn PDF document text
    • https://www.skyline-recruiting.com/wp-content/plugins/super-forms/uploads/php/files/7a5415c5059b14f0abb394685f6bda5a/vabegurozebewimoj.pdfIn PDF document text
    • https://www.elementstraining.co.uk/wp-content/plugins/super-forms/uploads/php/files/590sg1927pb2v9c12iet6ng7hi/65274709039.pdfIn PDF document text
    • http://panda-es.tokyo/yamituki-n/uploads/files/32225638154.pdfIn PDF document text
    • https://drivingschoolofnorthtexas.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608745ef3507b---42885928656.pdfIn PDF document text
    • http://nutrisoilvietnam.com/upload/files/96154008098.pdfIn PDF document text
    • http://bellsazshihtzu.com/clients/878694/File/rigosoguzosuluvitojisop.pdfIn PDF document text
    • https://ladychief.com/wp-content/plugins/super-forms/uploads/php/files/58f401362dea39478296f4385fb859f6/94243254802.pdfIn PDF document text
    • http://studiotecnicolari.it/userfiles/files/melamek.pdfIn PDF document text
    • http://charontrade.hu/data/file/zitanavudekomubiwimivem.pdfIn PDF document text
    • http://2016montemayorreunion.com/clients/e/e5/e530e98a7ee505477716bae2fe71cdef/File/japebobubavukiweliligin.pdfIn PDF document text
    • https://www.ideaklinikkadikoy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc5558f38d---32607613494.pdfIn PDF document text
    • http://thefutureofgolf.eu/wp-content/plugins/formcraft/file-upload/server/content/files/1607851e9a6f49---56612166265.pdfIn PDF document text
    • https://2greenchicks.com/wp-content/plugins/super-forms/uploads/php/files/2a4c0a5c8411dcf8b114d35bd501074b/76694971533.pdfIn PDF document text
    • https://naseeha.org/wp-content/plugins/super-forms/uploads/php/files/88288af059f88d7787f56556e762f667/govek.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000111c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x111C4 11204 bytes
SHA-256: 7ae414484c106bbe7d1209aea3005715f07b1019d30f0fa5111f4762a04ddb07
font_01_sfnt_off00012bd5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12BD5 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off000143e7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x143E7 21456 bytes
SHA-256: 5b884cfb266b8d741a7798d7d30974d45fa3a14f9c884ea6de9b5e5f4b0ef6ad