Malicious PDF — malware analysis report

Static analysis result for SHA-256 fea3f5ce1c4f2c4d…

MALICIOUS

PDF

94.7 KB Created: 2021-07-31 00:44:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-14
MD5: ab7cb09e9c6c662a81b091bc59bec6c1 SHA-1: 7c0b3f66b4947bde7922f5633c680400932f4c60 SHA-256: fea3f5ce1c4f2c4d77d0388a5e88feab16fbbbcc191654210a714d4753d74a46
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing attempt. It functions as a link farm, directing users to multiple compromised WordPress sites. The embedded URLs suggest an attempt to distribute further malicious content or lead users to phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9984

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160952cfca5ab9---rejuju.pdf In PDF document text
    • http://www.telsercom.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b05954bb065---zobobejoxafisudamuzadexiv.pdfIn PDF document text
    • http://gingerbreadvillage.org/clients/e/e3/e396b250b60561adcb946853f9f62e29/File/40127196685.pdfIn PDF document text
    • https://trsbarriersdirect.com/wp-content/plugins/super-forms/uploads/php/files/3s24ahccl39muj883gjlrpba0n/41212809818.pdfIn PDF document text
    • http://volareinmongolfiera.it/userfiles/files/1985148580.pdfIn PDF document text
    • http://highlandlynxotic.com/clients/7/73/73cf6ae24f8ea70eb1cbac1dff6b0f9e/File/nolozisazolofa.pdfIn PDF document text
    • http://johncarroll1967.com/clients/1/18/1896e795ecc2602204d707ec4e69586f/File/mapemotikito.pdfIn PDF document text
    • http://papianiarch.it/userfiles/files/tinogef.pdfIn PDF document text
    • http://klccpa.com/userfiles/file/65297184103.pdfIn PDF document text
    • https://isabellepieman.com/userfiles/file/95022165391.pdfIn PDF document text
    • https://demircanticaret.com/userfiles/file/79498810023.pdfIn PDF document text
    • http://alimentosldm.com/userfiles/file/ziruposubofawodelamexefo.pdfIn PDF document text
    • https://glbtrader.com/userfiles/file/7451745808.pdfIn PDF document text
    • http://www.gainerwindows.ca/wp-content/plugins/super-forms/uploads/php/files/bn9jb283maftd80oa615uabcj4/womivij.pdfIn PDF document text
    • https://visaonline-vn.com/wp-content/plugins/super-forms/uploads/php/files/5j688h7d751gp9l7mbfjsua90a/toluve.pdfIn PDF document text
    • http://rainbowcaterers.in/userfiles/file/zudozovokikujoxos.pdfIn PDF document text
    • https://rybczewice.pl/userfiles/file/nizedawixetebesizudure.pdfIn PDF document text
    • http://cementfeet.com/userfiles/file/3667067378.pdfIn PDF document text
    • https://www.asahinadigital.com/wp-content/plugins/super-forms/uploads/php/files/48of1g5v9vpmhg1ugdg3694fl3/kinevotadowapofa.pdfIn PDF document text
    • http://xn--90ad5ackt1d.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/b1236d8181351847c801bde0053dfd7e/zedosigebiwolenikujo.pdfIn PDF document text
    • http://aliceinformaticasrl.com/user/pages/tupuso.pdfIn PDF document text
    • https://jetzterstrecht.hamburg/wp-content/plugins/super-forms/uploads/php/files/b2udh9p10geafj4tjsj74ehhd5/72590171820.pdfIn PDF document text
    • http://aczelzalog.hu/tmp/76833830583.pdfIn PDF document text
    • https://stopserv.ru/files/file/goriromomujuxatif.pdfIn PDF document text
    • https://www.hintonassociates.com/wp-content/plugins/super-forms/uploads/php/files/5ae2321976ed4a1b9f43f1b79ef0c0d0/66016767781.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/BkSY9tpko7c/uplcv?utm_term=japan+drag+racing+3d+mod+apk+downloadPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010c3f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10C3F 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off00012456.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12456 10800 bytes
SHA-256: e84b9986ed8ba0c878a19942a3542efbf9bf38fc9336d8fedfe9c1d14e17a438
font_02_sfnt_off00013cfd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13CFD 17868 bytes
SHA-256: e5690234233e79f4c961a380978e5377c6e8fd8465bcfc5fd6b80af14ff198a4