Malicious PDF — malware analysis report

Static analysis result for SHA-256 37037b35c3f1690a…

MALICIOUS

PDF

86.0 KB Created: 2021-06-08 02:09:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: f119ec363c545e408d86cc7a9cb5a523 SHA-1: 507946ea293fac3efcf222004c8ca678dd956308 SHA-256: 37037b35c3f1690a23f2ebce2ea6c529dbe6ce45894d7ac910277b6476346453
226 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of numerous external links, including a link farm on disposable hosting, suggests an attempt to distribute malicious content or phish for credentials. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' strongly indicates that the document is designed to trick users into downloading a password-protected archive, a common tactic to evade initial security analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/123?utm_term=consumer+reports+login+free PDF link annotation
    • https://jasugupaxawuz.weebly.com/uploads/1/3/0/7/130740610/zuwigomijokuxu.pdfIn PDF document text
    • https://daxakowov.weebly.com/uploads/1/3/4/7/134704390/biwofutin_jukoromutasifim_rajuxakupo_xaduv.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4367635/normal_5fef3af5e2aba.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4453103/normal_603497f5cafe8.pdfIn PDF document text
    • https://sujujiga.weebly.com/uploads/1/3/1/3/131379538/cab5616d.pdfIn PDF document text
    • https://bevozuvegala.weebly.com/uploads/1/3/3/9/133999301/5159830.pdfIn PDF document text
    • https://zefimaral.weebly.com/uploads/1/3/0/7/130776827/8e0b63cb9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403129/normal_5fd8f4fad7715.pdfIn PDF document text
    • https://gitibufilunaj.weebly.com/uploads/1/3/1/4/131453558/78689e49537f.pdfIn PDF document text
    • https://jexolelogirif.weebly.com/uploads/1/3/4/9/134901145/taxife_lopoxitid_wibukuxeluf_bebonogesubezi.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4464700/normal_5fce59391ad84.pdfIn PDF document text
    • https://sufusazowuk.weebly.com/uploads/1/3/4/3/134311692/pisaxatukiki-lajapuxel.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470387/normal_5fff19c99588a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4463807/normal_5fd641976d2cd.pdfIn PDF document text
    • https://nilitimuxuzadox.weebly.com/uploads/1/3/4/3/134320754/5c27fc1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412896/normal_6009fa708d6a0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://lokifasowaso.pbworks.com/w/file/fetch/144726426/pass_simple_cm2_exercices_imprimer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d80f7b9f-3148-45c9-85bc-48f26db4816d/92540316336.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/063a5979-032e-4c1b-8492-6638a16bc597/3876910478.pdfIn PDF document text
    • http://xuwedateredu.pbworks.com/w/file/fetch/144824307/qual_a_diferena_de_adjunto_adnominal_e_adjunto_adverbial.pdfIn PDF document text
    • http://lekuzax.pbworks.com/w/file/fetch/144412233/14956861975.pdfIn PDF document text
    • http://lakebimutep.pbworks.com/f/24500522515.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e4be0938-3bc7-4759-b391-d4ea1158e521/montessori_and_other_teaching_methods.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a167bef2-86b4-4a1b-8741-38d0b0f0038a/9751714130.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b5b389ca-ea35-461b-80e5-54f480ec4927/are_all_kidde_smoke_detectors_compatible.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef22.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF22 4916 bytes
SHA-256: 5b8ed971b901bfb8d72508a8bab96e74960e72a73b7de95976c643b778cbe838
font_01_sfnt_off0000ffbc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFFBC 6148 bytes
SHA-256: 488ffee5e9c33bcc1f3f00aec749f35977d0cdd209ffadaee35194d66ecc177d
font_02_sfnt_off00010f9c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10F9C 13684 bytes
SHA-256: 578e00c5b7ab806f809edd70f763611682b7f79484e331980529d27e6de13694
font_03_sfnt_off00013be5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13BE5 4324 bytes
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f