Malicious PDF — malware analysis report

Static analysis result for SHA-256 fb13423a2eb7c02a…

MALICIOUS

PDF

82.5 KB Created: 2021-08-30 14:57:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-09-13
MD5: 640e52198e921f3bb78736396a33ead0 SHA-1: 47326f64d5964f3b7e6595a21c7c3307e3981b59 SHA-256: fb13423a2eb7c02a7635700e8e96acf1f87802741d4a717fffe88e37711d8a33
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection and an ML classifier. The heuristics indicate the PDF acts as a link farm, directing users to compromised CMS uploads and disposable hosting sites. The presence of numerous unknown URLs suggests an attempt to distribute phishing content or further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9974

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vasvaripalmuzeum.hu/upload/file/jakosekorefipenowukijek.pdf In PDF document text
    • https://www.bouwenaaneensterkwerkgeversmerk.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1608af872ba2f0---21243742629.pdfIn PDF document text
    • http://www.scmphotography.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/161281c16079c6---bazor.pdfIn PDF document text
    • http://eraucheta.ru/uploads/file/wexuxinapiwigam.pdfIn PDF document text
    • https://www.kasekimi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16073ac139a3cb---kovagifijezax.pdfIn PDF document text
    • http://szakkepzosiklos.hu/upload/file/wodepinatarezulafevuxiz.pdfIn PDF document text
    • https://aspirans.com/files/file/lewebupebegopilem.pdfIn PDF document text
    • http://digivideos.net/ckfinder/userfiles/files/82734189695.pdfIn PDF document text
    • https://youstore21.com/wp-content/plugins/super-forms/uploads/php/files/7d5be6c533374af1ddfc27e5394a4a52/zodirikajoriwusugaxisu.pdfIn PDF document text
    • https://badoza.net/userfiles/file/86180433991.pdfIn PDF document text
    • http://counterreaction.net/wp-content/plugins/formcraft/file-upload/server/content/files/160fa881119a39---56886741091.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16097d0bd07407---5293147042.pdfIn PDF document text
    • https://studiogreenwich.ru/wp-content/plugins/super-forms/uploads/php/files/54b9ef8c56c6f8ebb400eaabcebd269e/17378584492.pdfIn PDF document text
    • https://joyfool.art/wp-content/plugins/super-forms/uploads/php/files/51f56f4e93a86c052037c6c19759e25b/xevurolamalejixisigiv.pdfIn PDF document text
    • http://teplospectr.ru/images/files/piguze.pdfIn PDF document text
    • http://www.airportlimofortlauderdale.net/wp-content/plugins/formcraft/file-upload/server/content/files/160b6bec9266d9---gotuxuvoxanexatowejidodav.pdfIn PDF document text
    • http://vdgairconditioning.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1606f083c15de3---40380673859.pdfIn PDF document text
    • http://www.zav-mito.si/wp-content/plugins/formcraft/file-upload/server/content/files/160731ca77a08a---gimiga.pdfIn PDF document text
    • https://www.mii.net/wp-content/plugins/super-forms/uploads/php/files/afab406a26c94f529eeab5a61f8e882a/xozavafu.pdfIn PDF document text
    • http://balone.net/_upload/file///jexem.pdfIn PDF document text
    • http://babywagen24.de/userfiles/file/72535489269.pdfIn PDF document text
    • https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/160bd7f74ec3eb---zofejadufubeziwotazotu.pdfIn PDF document text
    • http://www.afamaresme.org/wp-content/plugins/formcraft/file-upload/server/content/files/1606df7ae74508---45955412930.pdfIn PDF document text
    • https://robotics-institute.com/wp-content/plugins/super-forms/uploads/php/files/uipqn165gu6f6j39l0j2b99l7u/61773343261.pdfIn PDF document text
    • http://brothersaluminium.com.np/wp-content/plugins/formcraft/file-upload/server/content/files/160b592108cfa0---39718737885.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/A3Ryygt5BCM/uplcv?utm_term=what+does+rtx+stand+forPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc39.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC39 10408 bytes
SHA-256: 03d5b5bf9b58f1e16af118814474d3c66c2ee032a62bca4aba7bd9d7c8a3a3ac
font_01_sfnt_off0000f3d0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF3D0 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00010be2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10BE2 18416 bytes
SHA-256: 8957332d3d04267763f3bf92a0d08a5612a9a11168b521e5270ebb421d974649