Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4d98bda382bd5b4…

MALICIOUS

PDF

82.7 KB Created: 2021-09-02 12:49:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-23
MD5: c9c00a9fe559e09599dcf267c4e23e98 SHA-1: d3b2993241e800fccc5e364b65f24f2953064ea0 SHA-256: e4d98bda382bd5b40a2be86a0ca268e4730a3adeced8fd8423b49b86c7238181
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier indicating maliciousness. It contains numerous external links, many pointing to compromised websites or disposable hosting, suggesting a link farm designed to redirect users. The presence of these links and the overall detection profile indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://laborke.ru/uplcv?utm_term=masculinity+and+femininity+theory+pdf PDF link annotation
    • http://dfh-consulting.com/userfiles/file/16553498411.pdfIn PDF document text
    • https://coastalholidayproperty.com/ckfinder/userfiles/files/6439426976.pdfIn PDF document text
    • http://pozitron-s.ru/userfiles/file/pesuf.pdfIn PDF document text
    • http://www.argentum.com/wp-content/plugins/super-forms/uploads/php/files/g2pr19le3mqcs9guhaph3jr4ic/nobomajit.pdfIn PDF document text
    • http://hebakotb.net/userfiles/file/91144405284.pdfIn PDF document text
    • https://bentzendesign.se/wp-content/plugins/formcraft/file-upload/server/content/files/1609da69e3f63f---lubomisonebinerazinu.pdfIn PDF document text
    • https://ewastexperts.com/userfiles/files/60387135985.pdfIn PDF document text
    • https://www.femregenx.co.za/wp-content/plugins/super-forms/uploads/php/files/cn4e2nip3rd1e0aals18r7iuii/11858748462.pdfIn PDF document text
    • http://www.gc-antey.ru/ckfinder/userfiles/files/rosem.pdfIn PDF document text
    • https://bibliotheque-des-arts.ch/ckfinder/userfiles/files/bokusisufazagigapituzap.pdfIn PDF document text
    • https://portsidestrategies.com/wp-content/plugins/super-forms/uploads/php/files/62d0876dcf27374bfe7a906588b45bcd/55917403066.pdfIn PDF document text
    • http://www.phonefixcomo.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085d9868a027---wudewexeke.pdfIn PDF document text
    • http://sevennews.com.br/ckfinder/userfiles/files/88908507069.pdfIn PDF document text
    • http://cedresarquitectura.com/wp-content/plugins/formcraft/file-upload/server/content/files/16114ab50475b2---tigoxovudovivi.pdfIn PDF document text
    • https://najlepsze-w-polsce.pl/uploads/mumosodebujujigosizaruj.pdfIn PDF document text
    • http://kursadowicz.pl/Upload/file/mugenekidodav.pdfIn PDF document text
    • https://aldea.work/wp-content/plugins/super-forms/uploads/php/files/5d5dd687310d22f0840fcd12b3112f75/gotas.pdfIn PDF document text
    • http://brnc85.com/clients/878796/File/dulasede.pdfIn PDF document text
    • http://wolfroccatiassociati.it/userfiles/files/sefepi.pdfIn PDF document text
    • https://b2cexpressdemo.com/userfiles/file/52562664579.pdfIn PDF document text
    • https://baodinhsolar.com/wp-content/plugins/super-forms/uploads/php/files/be1mjvpcrjcs7vdi999p0fit3c/60804827643.pdfIn PDF document text
    • http://thehawthornnyc.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607c6d325e64f---74391538299.pdfIn PDF document text
    • http://vizcsap.hu/files/file/digivawuge.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c335.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC335 11092 bytes
SHA-256: e7c1917dd1dd1ffd2e6823ae64f43986c33f57703844c1786c8c30896888ecda
font_01_sfnt_off0000dcee.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDCEE 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off0000f500.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF500 16372 bytes
SHA-256: 456919facbade7bf6a47b1a8fbd69ef0fc2e85d253631a901a05eaafb9c568c0
font_03_sfnt_off00011f45.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11F45 18532 bytes
SHA-256: 59a05cc234a75a81c52730d4e525866c76be2c82036908e8b3672b13822223f4