Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1c67920f9768c7d…

MALICIOUS

PDF

377.5 KB Created: 2021-05-10 07:56:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-04
MD5: f503d7944ef7b695146626224c4683fc SHA-1: 0a80a9af9b970f0259679ab0a4a5548e6e07c699 SHA-256: f1c67920f9768c7dbcb0112693c3455e036ce1e2ff0f10d7d66c74662e44d618
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm, many hosted on compromised CMS upload directories. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9847

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.temsilcisitesi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160749a095c8d1---97528764554.pdf In PDF document text
    • https://viajespereira.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074126395e17---61678164923.pdfIn PDF document text
    • https://izharfoster.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607248d8b66d3---78263697400.pdfIn PDF document text
    • https://maugli24.ru/wp-content/plugins/super-forms/uploads/php/files/96fa1a0c0e503432d2d7be8a7fdf729e/4340593479.pdfIn PDF document text
    • https://www.harasportcenter.com/wp-content/plugins/super-forms/uploads/php/files/1mihbjhv08323do7j4kp6kfcea/roguweniputali.pdfIn PDF document text
    • https://www.darrellstuckey.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ed3a69b65a---7542203737.pdfIn PDF document text
    • http://conservationenergy.com/wp-content/plugins/formcraft/file-upload/server/content/files/16077911980b9d---walakulixubedisaxejivu.pdfIn PDF document text
    • https://www.vedaaz.com/wp-content/plugins/super-forms/uploads/php/files/4a51028cd099a65062987cede7433ecb/46054038943.pdfIn PDF document text
    • https://drmarlenebothma.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1606fd89b8e01d---xisufibexumomevojufibet.pdfIn PDF document text
    • https://www.certificagreen.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608450bcbf0e2---78803370777.pdfIn PDF document text
    • https://extremetour74.ru/wp-content/plugins/super-forms/uploads/php/files/cb739750282d2cf949dfea17e83c2749/sedetob.pdfIn PDF document text
    • https://www.lokalesichtbarkeit.de/wp-content/plugins/super-forms/uploads/php/files/bugmeg2tue5mle9rul2qjd3h6a/13467469738.pdfIn PDF document text
    • http://www.sensible-seeds-premium.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607dfadfa1fc3---7528016911.pdfIn PDF document text
    • https://stpetejazz.com/wp-content/plugins/super-forms/uploads/php/files/hr2tbrm531r6c262dgb8r47829/nonufiwegubezuxodifixip.pdfIn PDF document text
    • https://alakharia.com/public_html/userfiles/file/56919843786.pdfIn PDF document text
    • https://www.couleurs-et-jardin.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160911a991d91f---togatopukofo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=a+boring+gift+94+percent+answersPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00057f6f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x57F6F 5616 bytes
SHA-256: 7ff2e273040fe95c29fd375f148ebfe33f7a266560364349e21b539dfb346aa0
font_01_sfnt_off000592b3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x592B3 13604 bytes
SHA-256: 3cbb175d2ce5a77a1cf97f25a4df8e6e64efefaf235ff02d33272f53c6a5c655
font_02_sfnt_off0005c094.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5C094 16388 bytes
SHA-256: 0c82561ead172ac0e51412abe629b5944d5f81f469066018c017fef234fe4ba7