Malicious PDF — malware analysis report

Static analysis result for SHA-256 e08d320d70e5f09a…

MALICIOUS

PDF

101.9 KB Created: 2021-04-30 05:20:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a31fa1fd75e8896de40b99dc9a311857 SHA-1: 9abf46fb20c122c65be1675efa2f09be7a691f10 SHA-256: e08d320d70e5f09a8844ba57a68c355c143359c8ab0d758d61b37d6dbe6d2270
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous links to external websites, many hosted on compromised WordPress sites, suggesting a link farm or phishing attempt. The ClamAV detection as 'Pdf.Phishing.Trojan' strongly indicates malicious intent. Although no scripts were explicitly extracted, the PDF structure and link farm behavior are consistent with techniques used to redirect users to malicious sites, potentially for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier clean score 0.1778

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://becro-plast.hr/wp-content/plugins/formcraft/file-upload/server/content/files/1606d0704c547f---3096863029.pdf
    • https://studio45.live/wp-content/plugins/super-forms/uploads/php/files/4am03pmknlqadb3spbariidhml/9965851502.pdf
    • http://www.onekaddy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607497cb2d8aa---gisolimosaw.pdf
    • http://antwerp-rentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/160752433c7038---sefomazitazafo.pdf
    • https://www.conkite.com/wp-content/plugins/super-forms/uploads/php/files/1e119736d6a8f476e0114f8624d0b32d/ruvabexajawa.pdf
    • https://formapolis.it/wp-content/plugins/super-forms/uploads/php/files/5637397cf9b4d1277848f4fbcc0107cb/vemubibipunojegotobolo.pdf
    • https://xn----7sbbjg7ctfs.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/850cbfc4ae8c45c1e84893bb681f1133/zogolefavu.pdf
    • http://www.reroofingbrisbaneqld.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16074022064a77---molopesexiwevulumifug.pdf
    • http://audiomaster.se/wp-content/plugins/formcraft/file-upload/server/content/files/160743b577ecdd---53778886519.pdf
    • http://chocolatycakes.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607ab40913f56---1431757175.pdf
    • https://seataclightingalaska.com/wp-content/plugins/super-forms/uploads/php/files/8164fad320dd9c9709cd6023a29f4a3b/81423909018.pdf
    • https://notofthisgalaxy.com/wp-content/plugins/super-forms/uploads/php/files/sh22bbss0aj1m9erfde5mh93og/64786560928.pdf
    • https://www.cfo-search.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086755c24066---jazivufabuxijuxepoxiko.pdf
    • http://entone.es/wp-content/plugins/super-forms/uploads/php/files/2d6de4869fe12dad1d7a49c1565ce4aa/11175997245.pdf
    • https://www.varishastalari.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a5b12686c6---zojemonulovexebede.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/skout/mBVl/~3/DOqCt-cVA4I/uplcv?utm_term=variables+terms+and+expressions+worksheet+algebra+2
    • https://bxthirteen.wpengine.com/wp-content/plugins/super-forms/uploads/php/files/3b2d7f34f541c88271901587909ec11f/vexinekalatej.pdf
    • http://scripts.sil.org/OFL
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011b70.bin
abe1bc026593589d28ee7a693b2b235bd01efbfbfc652762e209e998f2e0bdbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x11B70 3164 bytes
font_01_sfnt_off000126a9.bin
d0da3cc57ba2947bf1437e765c92ceaa5e621896573dc9dbc8d5cdfd214c652e
pdf-font-stream PDF embedded font (sfnt) at offset 0x126A9 5836 bytes
font_02_sfnt_off00013a30.bin
6d1a48754ad47e2fdfc9ff23dac853edceaa38851969315d0754ce36e7ae49a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x13A30 6300 bytes
font_03_sfnt_off000149a3.bin
c16ec9a9d1965d30a3c2d0f2c2e5ddca7f8da333dd2142c1134aa06e497cbfd8
pdf-font-stream PDF embedded font (sfnt) at offset 0x149A3 14052 bytes
font_04_sfnt_off000179aa.bin
ba16d64f443317bdb0ee9217fb56ab862d25af33a6560ec484c2427d092c82a8
pdf-font-stream PDF embedded font (sfnt) at offset 0x179AA 16440 bytes