Malicious PDF — malware analysis report

Static analysis result for SHA-256 f94f170794060083…

MALICIOUS

PDF

91.8 KB Created: 2021-09-01 01:57:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 293af5dfe22f98708fa8a6b313754483 SHA-1: b364cad84de30c31a59841d19ebbccdebfcc05a7 SHA-256: f94f170794060083045abd9a77f1c2988f7c17aa9b300d93bac6ee8c43319582
172 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded JavaScript and numerous links, many pointing to compromised WordPress sites, suggesting it's part of a phishing or malware distribution campaign. The presence of a visual download button further supports a lure-based attack pattern. The ClamAV detection as 'Pdf.Phishing.Trojan' strongly indicates malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 8

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bouveau-consulting.com/userfiles/file/55275732200.pdf
    • http://salonlomi.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160e2e61db5c8e---gufixuxawuvunirex.pdf
    • http://sbox-technology.com/upload/datoteke/66590434722.pdf
    • http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ad6ea48c91---woduja.pdf
    • http://walker-doss.com/clients/4/45/450b4a4af5ff3f13851793278d9c7ef8/File/61403064610.pdf
    • http://www.opencalgary.org/wp-content/plugins/formcraft/file-upload/server/content/files/16095fe51e290b---30446549490.pdf
    • https://haps.company/wp-content/plugins/super-forms/uploads/php/files/g0aai6formhvp9druqibmibji1/39503150585.pdf
    • http://omni-links.com/images/blog//file/38873069291.pdf
    • http://albino-pitti.com/pub_img/file/pozuvevuxelusowisojizevup.pdf
    • https://pabausa.org/wp-content/plugins/formcraft/file-upload/server/content/files/160923c51c532e---29100566213.pdf
    • https://www.webhisto.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16098bb1f064d1---75928558376.pdf
    • http://akifkasaboglu.com/esatfisek/images_upload/files/vinikuzanojivem.pdf
    • http://www.jhannahs.com/wp-content/plugins/formcraft/file-upload/server/content/files/160840332395cd---32362914134.pdf
    • http://www.qookspot.kitchen/wp-content/plugins/formcraft/file-upload/server/content/files/16091920385da7---xojukig.pdf
    • http://446888.top/userfiles/file/pimunasekeji.pdf
    • https://www.hotwaterfactory.com.au/wp-content/plugins/super-forms/uploads/php/files/7af8e939af39653eb250a6f7a54b11d6/26421552541.pdf
    • http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607dafb958da5---vapixepuruzurig.pdf
    • https://www.cocochan.com.pk/wp-content/plugins/super-forms/uploads/php/files/7e2b4221e271e0b0598a81a98c97197a/47170338665.pdf
    • http://t-p-fortune.com/userfiles/file/wudejupen.pdf
    • http://www.kinoimaging.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16095a76eab64d---95403291055.pdf
    • https://www.projectorrentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0d4dd2063c---87085296376.pdf
    • https://cpc-serbia.org/js//files/34702089680.pdf
    • http://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094dea798994---xivuwekojogevokig.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=all+competitive+exams+maths+tricks+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fd03.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD03 16792 bytes
font_01_sfnt_off00011515.bin
4deda87346d82a50e242f013dc15c0b0b5a8745c7ff0045b7dbc1ec968978ad5
pdf-font-stream PDF embedded font (sfnt) at offset 0x11515 19196 bytes
font_02_sfnt_off00014771.bin
796446d48ca66bd52f1ac53e25a3415ea387dbd13720af5f6dbb2daeeed623f7
pdf-font-stream PDF embedded font (sfnt) at offset 0x14771 11024 bytes