Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7df3cf4a5e87724…

MALICIOUS

PDF

87.2 KB Created: 2021-09-01 01:03:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-16
MD5: d69b31a1b6547da2ab047cdd24c9607d SHA-1: 6756da9e1b404ca94ee372023a085a1d97af5724 SHA-256: f7df3cf4a5e87724541df3078a7adb6c9af60415155a581fa089582b9d178c0a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains numerous external URIs, many of which point to compromised WordPress sites. The ML classifier strongly indicated maliciousness, and the structure suggests a link farm designed to redirect users. The presence of multiple compromised CMS upload links further supports the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://chcial.ru/uplcv?utm_term=12th+science+textbook+pdf PDF link annotation
    • http://www.communityheroesproject.org/wp-content/plugins/formcraft/file-upload/server/content/files/1611b416224774---fuvazalisetoxuwezugubara.pdfIn PDF document text
    • https://hiampelectric.com/wp-content/plugins/super-forms/uploads/php/files/e233a4f977e866fcbfdf01f2f2b8a257/98949471689.pdfIn PDF document text
    • https://markzone.az/wp-content/plugins/super-forms/uploads/php/files/nf1356snnotkkcan6ld8b0ulpn/82650265982.pdfIn PDF document text
    • https://lynnesnaturaltreats.com.au/wp-content/plugins/super-forms/uploads/php/files/d53c8cb5e7bfb652731fa987a4978a83/8921983434.pdfIn PDF document text
    • https://mariellatriolo.it/public/file/55059966007.pdfIn PDF document text
    • http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609d0762920d7---fepudani.pdfIn PDF document text
    • https://yarsan.ru/wp-content/plugins/super-forms/uploads/php/files/86ca249b0151206c49e2c1cc98ff2d09/maruxakuxotetajelalekix.pdfIn PDF document text
    • https://xn--z4qq44i.xn--kpry57d/upload/actfiles/mizepipisi.pdfIn PDF document text
    • https://wurstfargo.com/wp-content/plugins/super-forms/uploads/php/files/0875fb3caa1018b9bcef12048f8c087e/dakajosuwexigifobitezixe.pdfIn PDF document text
    • https://people11people.gr/uploads/File/72749407260.pdfIn PDF document text
    • https://truck-diagnostic.ru/wp-content/plugins/super-forms/uploads/php/files/2387e63453418609981e71a93f070b48/63513706324.pdfIn PDF document text
    • https://mfdesign.hu/files/file/48481251964.pdfIn PDF document text
    • http://nwatchonline.org/userfiles/file/mifak.pdfIn PDF document text
    • https://khogiaydantuonghanquoc.com/images/news/file/70670342377.pdfIn PDF document text
    • http://congtrinhnhaviet.vn/upload/files/75471680035.pdfIn PDF document text
    • http://papinchess.ru/userfiles/file/nakabirefaremof.pdfIn PDF document text
    • https://parklanehotel.asia/userfiles/file/25927602814.pdfIn PDF document text
    • https://sirikulsteel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160857ea80fb82---lodeguwevibume.pdfIn PDF document text
    • http://studiolauramoschini.it/userfiles/files/39675985020.pdfIn PDF document text
    • http://www.jindatunnel.com/up_files/file/mikidivetozepabagidi.pdfIn PDF document text
    • https://paloaltospeakerseries.com/wp-content/plugins/super-forms/uploads/php/files/b4890bc94282e4feb06c26a6433e4323/20104849331.pdfIn PDF document text
    • https://akbaturgame.com/calisma2/files/uploads/tewadomimo.pdfIn PDF document text
    • https://sevsport.info/wp-content/plugins/super-forms/uploads/php/files/a07c020b6503084584c18b900e78bb73/80447828285.pdfIn PDF document text
    • http://entone.es/wp-content/plugins/super-forms/uploads/php/files/f9c85594db05f1affe28e8ab0c28cc87/12657460035.pdfIn PDF document text
    • https://akdenizokullari.k12.tr/wp-content/plugins/super-forms/uploads/php/files/26s6rdh8mlaut7n634krr12run/48638680712.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed59.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED59 10820 bytes
SHA-256: c0b1ca451dd5069a57660808de541e91196f1c53f63db89272ae090cef226467
font_01_sfnt_off00010619.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10619 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00011e2b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11E2B 18712 bytes
SHA-256: 5da476f3154e909d41b84c34a0d8c61fcb78ee4e80b9ad33f1e19cfb3195fad1