Malicious PDF — malware analysis report

Static analysis result for SHA-256 f104c3c3bb024fe1…

MALICIOUS

PDF

697.1 KB Created: 2021-07-13 20:54:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: b9e17f9e8fab1987c4339b3592f87897 SHA-1: 2a2bb4cd96d3c2a16c4b324a036cc10a3ceb19f9 SHA-256: f104c3c3bb024fe15d70d8c72bbd2dd1672b9cbbf0d81f580d0f097aebd27a20
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The file was detected as malicious by ClamAV and an ML classifier, with heuristics indicating it contains a link farm pointing to compromised WordPress upload storage. The PDF document itself contains no readable content, but the presence of numerous links to potentially malicious PDF files hosted on compromised sites suggests a phishing or malware distribution attempt. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6898

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.onegelha.com/wp-content/plugins/super-forms/uploads/php/files/cd0904aafa533e1e98c8b1f7ffe1a8e5/lewejoripitemajisaxituwek.pdf
    • http://math-talk.kr/wp-content/plugins/super-forms/uploads/php/files/ofg6mmulk792eo43gub0aho7nu/xuvebuzu.pdf
    • http://bielwod.com/userfiles/file/vakusitidebivafagukux.pdf
    • http://seoulsquare.com/userfiles/file/66215172450.pdf
    • https://gz-topstar.com/wp-content/plugins/super-forms/uploads/php/files/34482fb41e3fcd056e141b90d9cea806/xagujis.pdf
    • https://rffsev.ru/wp-content/plugins/super-forms/uploads/php/files/ad56311cdd7705f083620728816bf5af/8234131757.pdf
    • https://bomberosdenavarra.com/userfiles_nexo/files/zefudusexavoxegomova.pdf
    • https://hiroyoung.com/data/files/59539856752.pdf
    • http://epoxidice.ro/mm/file/viranofutopipap.pdf
    • https://rclurie.com/wp-content/plugins/super-forms/uploads/php/files/26cce3ccb8e7e41d938bbcd6b29de010/forusagi.pdf
    • http://www.serenissimaservizi.com//files/83595763364.pdf
    • https://alkhairi.co.uk/wp-content/plugins/super-forms/uploads/php/files/0891311b42547ef69a1466efed4b5672/vatusonodemepat.pdf
    • http://www.appsolutely.sg/wp-content/plugins/formcraft/file-upload/server/content/files/160874c7493d60---58959581679.pdf
    • https://www.focus.mu/wp-content/plugins/super-forms/uploads/php/files/be52589eeecd1cecf3007e5e9548972a/68856985435.pdf
    • https://seeyounow.net/userfiles/file/30406138424.pdf
    • http://hani-bee.com/userfiles/files/91020565239.pdf
    • http://broadviewlibrary.org/uploaded_bvlib/file/42020137735.pdf
    • http://hevolta.com/upload/file/67020393983.pdf
    • https://assurancemauricie.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f411b01da4---23566143417.pdf
    • http://jinanxintiandi.com/userfiles/files/97281169146.pdf
    • https://markeishahall.com/wp-content/plugins/super-forms/uploads/php/files/2c61e1e23329c5d243563dcc4ea4a142/mizeledo.pdf
    • https://evocative.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160dcda730c821---foworebujedakakopixog.pdf
    • https://fmpride.com/wp-content/plugins/super-forms/uploads/php/files/b20d3a90e177555b506f50b19ae4907d/15981888173.pdf
    • https://hondaotohaiphong.vn/upload/files/71084311034.pdf
    • http://ophirtonhotel.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160879bf0255f8---xubixatezuxedup.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/A3Ryygt5BCM/uplcv?utm_term=confidence+in+reason
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0009f377.bin
086c1d1f1343c191cf0c7be5a6b5e827f4f6efde1a0cfe8f579f551bba10a069
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F377 10356 bytes
font_01_sfnt_off000a0af6.bin
44552ccb1f103435fa3dd70260c88236b38a563549c3f2eeb25f068d4bbd4556
pdf-font-stream PDF embedded font (sfnt) at offset 0xA0AF6 48452 bytes
font_02_sfnt_off000a8a02.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xA8A02 16792 bytes
font_03_sfnt_off000aa220.bin
20817403c17d5fd786501918f7a1fc06a12ce1e95afbf3f53c7f0553069729cf
pdf-font-stream PDF embedded font (sfnt) at offset 0xAA220 18276 bytes