Malicious PDF — malware analysis report

Static analysis result for SHA-256 f067b81967f8d937…

MALICIOUS

PDF

85.8 KB Created: 2021-08-04 01:01:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-24
MD5: 1755e8916c64bf5198cee08dd3be1e90 SHA-1: 5462b6730a192f4f7da0c5b13899b0a20cec4674 SHA-256: f067b81967f8d937ddc40dd007407cf1ea3955d38f853f491909f8ff2e6b8237
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs, many of which point to compromised CMS uploads or disposable hosting, indicative of a link farm. The presence of embedded JavaScript, flagged by heuristics, suggests the potential for malicious actions beyond simple redirection. ClamAV detection as 'Pdf.Phishing.Trojan' further supports a malicious intent, likely related to phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nepalaviationmuseum.com/userfiles/files/82796514051.pdf In PDF document text
    • http://rolfingnaples.com/clients/a/a5/a5422f62036d2d393d866963e902351c/File/51562926098.pdfIn PDF document text
    • https://dgaspcsm.ro/ckfinder/userfiles/files/mejovafuzulunidokulosozav.pdfIn PDF document text
    • https://wietsevoermans.nl/ckfinder/userfiles/files/kiredililaje.pdfIn PDF document text
    • http://comicpapyrus.com/wp-content/plugins/super-forms/uploads/php/files/48a29ff0dd1cc93a681a926d13868106/62479121269.pdfIn PDF document text
    • http://3duct.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c5fadd9a050---pogifu.pdfIn PDF document text
    • https://tirthmobile.com/wp-content/plugins/super-forms/uploads/php/files/qp51numlu5dhij3q3tsgtg34v5/67427801796.pdfIn PDF document text
    • http://hotelborgodeipoeti.com/userfiles/files/29140072297.pdfIn PDF document text
    • https://tour-paris-guide.com/cite_imgs/file/gagekamakirawulewule.pdfIn PDF document text
    • https://www.cfo-search.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d46ba059dbb---xolazatizawifujewegez.pdfIn PDF document text
    • https://www.hungryalex.com/wp-content/plugins/super-forms/uploads/php/files/2uikh4cjiijmisg0upd0r79dh6/dolodisarafowitefekakap.pdfIn PDF document text
    • http://sellmysayarah.com/userfiles/files/gumivosudo.pdfIn PDF document text
    • https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/9fdb87cc89e09b30d219e38a9d2a13d7/kadesojunopikeledulutas.pdfIn PDF document text
    • https://rebates.forex/wp-content/plugins/super-forms/uploads/php/files/dbt9u6gqecirh877i1vmr7da24/88327691860.pdfIn PDF document text
    • https://investainternational.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608d53e835cbb---bidojaraborojutana.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608d88fc385bd---18025441321.pdfIn PDF document text
    • https://perfecthospital.org/FCKeditor/file/61139236230.pdfIn PDF document text
    • https://microfocus-realize2020mea.com/wp-content/plugins/super-forms/uploads/php/files/b3d3832d11913bc30247f7e59fbfa5ac/pujatelelowogujigupajiv.pdfIn PDF document text
    • http://penzionriverside.cz/files/file/jufapajutugulusitekelijik.pdfIn PDF document text
    • http://plusk-car.com/js/upload/files/29750740974.pdfIn PDF document text
    • http://studioturina.com/userfiles/files/nabavefanaxozewug.pdfIn PDF document text
    • https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d87ecfe2c9d---31888073157.pdfIn PDF document text
    • http://famcareconnect.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607b210c023b5---lujavasobonobajutewuropa.pdfIn PDF document text
    • http://erkerlaender.de/wp-content/plugins/formcraft/file-upload/server/content/files/160c9cd4e2146d---nurogodonowa.pdfIn PDF document text
    • http://robwalker.net/fckupload/file/38126123571.pdfIn PDF document text
    • https://cafesca.org/ckfinder/userfiles/files/97559829113.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/A3Ryygt5BCM/uplcv?utm_term=facebook+logo+for+business+cardsPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec14.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC14 10864 bytes
SHA-256: 8370dc8ddd8c89e977a40536d0442985444baf35630054ae87d084f238cf4fba
font_01_sfnt_off0001050d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1050D 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00011d1f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11D1F 17012 bytes
SHA-256: 9894bcd5004f8421c4eff6df5794c7e02afa45af68965a68fac292d4a3325d80