Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7e472492cc06e47…

MALICIOUS

PDF

89.6 KB Created: 2021-09-01 00:59:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-14
MD5: 9ba45c2803fa728f77a2e1e26e02534f SHA-1: 490c4c57b3bc01ada563b393cdd079196afa8f0e SHA-256: f7e472492cc06e47ae497e2b9703983c8bfb80bcded4fdc42b9472adcdd77e36
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The ML classifier strongly indicated maliciousness in this PDF. Heuristics identified it as a link farm pointing to compromised WordPress upload storage and other disposable hosting, suggesting a distribution point for malicious content. The document body was unreadable, but the presence of numerous links to potentially compromised sites indicates a likely attempt to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 6

  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://miyagi.chi-kara.net/Upload/files/67004695631.pdf In PDF document text
    • https://www.nobleorthodontic.com/wp-content/plugins/super-forms/uploads/php/files/f10d9cef428e5f4d4c10be70affca860/22144910321.pdfIn PDF document text
    • http://www.johnknox.ch/wp-content/plugins/formcraft/file-upload/server/content/files/1607b3894ea9d5---14391527434.pdfIn PDF document text
    • https://www.sabiamente.es/wp-content/plugins/formcraft/file-upload/server/content/files/160adafa012dde---panibolifogifom.pdfIn PDF document text
    • http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/1609444b8272cd---39242786723.pdfIn PDF document text
    • http://romento.com/uploaded_files/userfiles/files/xorokamepivolatunuzavuf.pdfIn PDF document text
    • http://mikomisushiwc.com/uploads/files/gapekola.pdfIn PDF document text
    • http://ovartec.com/wp-content/plugins/formcraft/file-upload/server/content/files/160727ab8adfd6---97697505385.pdfIn PDF document text
    • https://ncfouting.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d63206bcfaa---94969867496.pdfIn PDF document text
    • https://popa.com.br/wp-content/plugins/super-forms/uploads/php/files/6536745cb62f1fe353df5d3b24069cd0/10165033457.pdfIn PDF document text
    • https://anmimar.com/royal/userfiles/file/xinajew.pdfIn PDF document text
    • https://bokaichenyu.com/upload/files/32655562416.pdfIn PDF document text
    • http://www.maoles.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a58fae5e374---81602663879.pdfIn PDF document text
    • http://www.expo-hotel.com/english/wp-content/plugins/formcraft/file-upload/server/content/files/160b2687b10a4a---subawakobevudunijuxis.pdfIn PDF document text
    • http://school19-zav.ru/userfiles/file/68323319357.pdfIn PDF document text
    • http://cukiernia-waltar.pl/qcms/userfiles/file/sopetaxamawomemepixefajo.pdfIn PDF document text
    • http://breakevenpoint.pl/uploads/editor/file/38123897069.pdfIn PDF document text
    • https://hotelritariccione.it/wp-content/plugins/formcraft/file-upload/server/content/files/160b494f485158---tobijakeru.pdfIn PDF document text
    • https://ceilford.org/wp-content/plugins/super-forms/uploads/php/files/c934fcd8d1d558bd4c88893adeda6886/70355716656.pdfIn PDF document text
    • http://firegallery.ru/img/upload/31251213304.pdfIn PDF document text
    • http://trackeg.com/en/wp-content/plugins/formcraft/file-upload/server/content/files/16094ca82aa5c4---jinukurasizevamin.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/cv9VXjIrmdE/uplcv?utm_term=hiv+cure+2020PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f9ed.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF9ED 9924 bytes
SHA-256: 8657e446addee0ddeae175579fee7c3eb12c6c59c9960edb3118421078f55f39
font_01_sfnt_off00011000.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11000 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00012812.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12812 18536 bytes
SHA-256: 3b7438abcd35ea4c5979d865d123cb166b9abbb142f297f70dc5b8c35fb0b6bc