Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6caaa059e19b502…

MALICIOUS

PDF

245.8 KB Created: 2021-06-09 06:32:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-16
MD5: a72d4839c0f0d8f711410ef45aa417f5 SHA-1: 0966d034bb91c5adda228b1f4911897b591b00bd SHA-256: f6caaa059e19b50268e5fa0703f838aa09d766771114a43ee65f096be4fc0e4c
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains multiple links to external websites, some of which are hosted on compromised WordPress sites, suggesting a phishing or malware distribution attempt. The presence of urgency lures and the ClamAV detection as 'Pdf.Phishing.Trojan' further support this assessment. Although no scripts were explicitly extracted, the embedded URLs and the nature of the heuristics indicate a likely attempt to redirect the user to a malicious site for further compromise.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3247

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ketchas.ru/uplcv?utm_term=dangerous+woman+album+download+mp3 PDF link annotation
    • http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/16083a8ed73053---vomepejuponef.pdfIn PDF document text
    • http://hondasushi.com/uploads/files/milimilezimevelijokabuw.pdfIn PDF document text
    • https://skazkavdom.com/wp-content/plugins/super-forms/uploads/php/files/56094dbf53c697e9200345ca9a601ff8/56633085152.pdfIn PDF document text
    • https://enville.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609e09f1dec8b---32660055466.pdfIn PDF document text
    • https://spectrumohio.com/wp-content/plugins/super-forms/uploads/php/files/7b3724b7871c29b30127177dc9bacfd1/xuvuvewuvevuv.pdfIn PDF document text
    • http://guides2alpes.fr/uploads/file/83748551272.pdfIn PDF document text
    • http://fabrykakonwersji.pl/wp-content/plugins/super-forms/uploads/php/files/cb600615be354b19d99e093752945e11/xizumibelufupemiligukavu.pdfIn PDF document text
    • http://www.dadosefatos.net.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608a44fae94cf---73764971224.pdfIn PDF document text
    • http://a2itsolutions.com/chop/multimedia/userfiles/file/12188314170.pdfIn PDF document text
    • http://www.holzbau-hoelzl.at/wp-content/plugins/formcraft/file-upload/server/content/files/160ab32b3b944b---53919942449.pdfIn PDF document text
    • http://3duct.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b8b2f35b704---71380833788.pdfIn PDF document text
    • https://encouragingmath.com/wp-content/plugins/super-forms/uploads/php/files/e427a84c64021ee26e66826e0f252e19/fezuxak.pdfIn PDF document text
    • http://consoles-a-gagner.com/fckeditor/userfiles/file/gokizavafe.pdfIn PDF document text
    • https://homeaestheticsllc.com/wp-content/plugins/super-forms/uploads/php/files/dd56956c8be7c4a12d0b56bab6d2cc16/xuboxuguwoz.pdfIn PDF document text
    • http://bollywoodsalonskokie.com/admin/images/file/jedamalejarerowo.pdfIn PDF document text
    • http://www.peopleoftheheath.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a2bf5d045c---negatutepozadigolofed.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHongIn PDF document text
    • http://www.geocities.com/dnhhngIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://scripts.sil.orgIn PDF document text

Extracted artifacts 17

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_017_off000370ee.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x370EE 22432 bytes
SHA-256: 23634b3dc6dfbcb1679fe953cf59441943ec2b42219f9e3ddeb2e893fd337f6a
font_00_sfnt_off0002474a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2474A 9984 bytes
SHA-256: be92c9181356d90dd2b250832f76c307ffbcad5b9bb7f21c589f6e0341c1552a
font_01_sfnt_off000261da.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x261DA 7652 bytes
SHA-256: 0a9e7902331d6ba60637fe3521c2d987039784d364f30e5f8186cc14695aa5ac
font_02_sfnt_off00027c62.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x27C62 5672 bytes
SHA-256: 86bc35eb6dd08e6255719ddd590a9626430b576da39d0551c5d6cefa752828a6
font_03_sfnt_off00028fa7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x28FA7 3984 bytes
SHA-256: 9a555929d543a0493a2fbf3f6eab5e2f7ee4d6276607878aec030325c91ec105
font_04_sfnt_off00029e22.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x29E22 5228 bytes
SHA-256: 4fa86c42bf26ff7825d1a0e926543e8e77dfcb3ac9be12c564b5d066dbfc814a
font_05_sfnt_off0002af2f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2AF2F 4156 bytes
SHA-256: 3960364835235b68a7092c767a91da9b3066e99464bfcb2ae6370750d7ff4e82
font_06_sfnt_off0002beea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2BEEA 6168 bytes
SHA-256: 709f3d7912930ac7d3d512f8e788e5cf5481a831ffa70d16368bb3611fa54f6e
font_07_sfnt_off0002d0d8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2D0D8 3812 bytes
SHA-256: f49e2acdaf820424ce96bcc3ac911740e77c1028928fa809775cdc4e4fed2ec4
font_08_sfnt_off0002df91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2DF91 2868 bytes
SHA-256: fff3bd6106556817e5b1499c33ca9b3cc4f36bebe9126150629418df2eaf6fee
font_09_sfnt_off0002eb5c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2EB5C 6124 bytes
SHA-256: b43ad04d252c450efb171f5d0055d3efe17833d40dbb20e45f786143a39d1d27
font_10_sfnt_off00030024.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x30024 3688 bytes
SHA-256: b5c5b4c0f62db548d8cd4e79d91422fe461e86acfc8551ff5bc3df8afe9426f8
font_11_sfnt_off00030eec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x30EEC 5016 bytes
SHA-256: 900975d269d20de7dfe9aa17c8f506936d31302a2d1dffe51320925fc7ccee2d
font_12_sfnt_off00031efa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x31EFA 7900 bytes
SHA-256: 94b2c0947b04cf1cfb726bec442a873dc842b82577aaa06c769fbf1dc1bb9fea
font_13_sfnt_off00033505.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x33505 20632 bytes
SHA-256: fd50dbf324e223be6bfe7f9622429f8ace935b2c3560676c3aaf4a3834d337ae
font_15_sfnt_off00039b98.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x39B98 5660 bytes
SHA-256: f9d46c909041fb547b7332658fe8ba564f6d914eed433ca58b04ac9f7d1e36da
font_16_sfnt_off0003b001.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3B001 5484 bytes
SHA-256: 024c173b39946bac647e7e9596822405614b333e5dc038c0eefdba863e790b73