Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee9f6e22a2a44886…

MALICIOUS

PDF

94.1 KB Created: 2021-08-10 00:15:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-16
MD5: 0009e33a9fe87d114a029ffca52d7aa9 SHA-1: b925360995d26e2938c0da6115a4d4604cdd0881 SHA-256: ee9f6e22a2a448860a79a22f55cd0293f8bf621d4dac992743999b54151d4bd3
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs, many pointing to compromised CMS upload directories, suggesting a distribution mechanism for malicious content. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' indicates the document likely instructs the user to decrypt a password-protected archive, a common tactic to evade static analysis. While no scripts were directly extracted, the presence of external links and the password lure strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9968

Heuristics 7

  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://chcial.ru/uplcv?utm_term=free+rose+paper+flower+template+svg PDF link annotation
    • http://mcutech.net/files/69538584246.pdfIn PDF document text
    • https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607370d567f1a---18039673881.pdfIn PDF document text
    • https://agrotehholding.ru/wp-content/plugins/super-forms/uploads/php/files/18759cfad6ce5647f48899d550bcfe11/dawilesotum.pdfIn PDF document text
    • https://thefertilizerequipment.com/d/files/1247348948.pdfIn PDF document text
    • http://xn----7sbakif2a3azdub.xn--p1ai/admin/ckfinder/userfiles/files/27279352807.pdfIn PDF document text
    • https://advicezone.org.uk/wp-content/plugins/super-forms/uploads/php/files/ludh6jcmdct8gsudueu2cqbdvv/julojoviroxubejedivaro.pdfIn PDF document text
    • https://taiwancy.com/app/webroot/userfiles/files/gatudanapelibogejan.pdfIn PDF document text
    • https://remoteworkerclub.com/wp-content/plugins/super-forms/uploads/php/files/4a426d2055dc006a00fd377d84c43a52/95175330492.pdfIn PDF document text
    • https://girl0229960192.com/upload/users/files/waromakomil.pdfIn PDF document text
    • https://www.siemers-deutschmann.de/wp-content/plugins/super-forms/uploads/php/files/1pboouddga3bhf8md6k2muocib/11965275682.pdfIn PDF document text
    • https://www.audifonosdoshoydos.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb3923868ce---kiriregedikogumefiwa.pdfIn PDF document text
    • http://saxonrt.hu/img/userfiles/files/resozasozonigibirurefa.pdfIn PDF document text
    • http://e-hematologica.com/users//file/28925726878.pdfIn PDF document text
    • https://dipinkrishna.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f4bef89ac9---tuziwiradaze.pdfIn PDF document text
    • http://df-foundry.net/d/files/40048587027.pdfIn PDF document text
    • http://drinkandshrink.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16086bd5796ddd---25891380417.pdfIn PDF document text
    • http://aromamahabaleshwar.com/ckfinder/userfiles/files/94249595861.pdfIn PDF document text
    • http://1000projects.ru/upload_picture/file/83330298297.pdfIn PDF document text
    • https://erinmillssmilesdentistry.com/wp-content/plugins/super-forms/uploads/php/files/4jstcjptmpqn3chuc72gb8oi01/9145137235.pdfIn PDF document text
    • https://amirep.com/wp-content/plugins/super-forms/uploads/php/files/48ca9fc2f9b87c78386f90e755381fea/jokavofatujirewibujo.pdfIn PDF document text
    • http://dzbnf.com/upload/file///46460792807.pdfIn PDF document text
    • http://mmbc.cz/_data/user_files/file/18034204318.pdfIn PDF document text
    • https://cruiseship.cruises/wp-content/plugins/super-forms/uploads/php/files/fnppt8tv61pb5terb5r0s709k9/xexexisaxibiji.pdfIn PDF document text
    • http://thehonourride.com/clients/c/c2/c2a221447f3e921143a55eca482c8289/File/moxobilitazikuwoga.pdfIn PDF document text
    • https://tailormade-sales-marketing.com/userfiles/file/bepopetexawesazowarasi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010b8f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10B8F 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off000123a6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x123A6 10636 bytes
SHA-256: 908e351f27f05f70455172be1238284d220ecebb4b775505e954e4dcc5ea9545
font_02_sfnt_off00013c24.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13C24 17280 bytes
SHA-256: 624d9a2d51e462976ebb12fe699ee18ec608f7ba2619202399a65d1ce350d436