Malicious PDF — malware analysis report

Static analysis result for SHA-256 05b29b1c24699284…

MALICIOUS

PDF

66.8 KB Created: 2021-03-04 14:58:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 6b0df5a8b5014c7a7972ddf0391bfd2e SHA-1: a41f5601a7d1e6befb583c396831c54de5901599 SHA-256: 05b29b1c24699284ae19e52380d41cce0ba03dc358093607c1d968747e115a64
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to 'ponafet.ru', which is suspicious. The document body, though heavily obfuscated, suggests a lure related to 'Jetblue ipo valuation case study solution'. No scripts were extracted, but the presence of external URLs indicates a potential phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6428

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=jetblue+ipo+valuation+case+study+solution PDF link annotation
    • https://murozukuzofapu.weebly.com/uploads/1/3/4/7/134716639/kuxinuxi.pdfIn PDF document text
    • http://xeboxemovev.66ghz.com/87721418026.pdfIn PDF document text
    • https://cdn.sqhk.co/mafowixodi/qGLxYhe/3d_puzzle_harry_potter_hogwarts.pdfIn PDF document text
    • https://cdn.sqhk.co/guvelebul/i5rjh7W/12975144.pdfIn PDF document text
    • https://nidabiweni.weebly.com/uploads/1/3/4/8/134865500/vimerava-jekoko-ropupusegulas-xobuxamebese.pdfIn PDF document text
    • https://cdn.sqhk.co/kafekogi/InhhhbX/multiplayer_car_driving_simulator_hack_apk.pdfIn PDF document text
    • http://wowunoli.22web.org/witevuvozojesif.pdfIn PDF document text
    • http://kopawaruda.22web.org/dawuruboruwolemikowug.pdfIn PDF document text
    • https://selegisazo.weebly.com/uploads/1/3/5/3/135323244/jiginepinizupufuban.pdfIn PDF document text
    • https://s3.amazonaws.com/tibitexil/jogos_pc_completos_utorrent.pdfIn PDF document text
    • https://s3.amazonaws.com/timeziso/6777914902.pdfIn PDF document text
    • http://lijukogibedatu.epizy.com/xulemave.pdfIn PDF document text
    • http://xuxusemo.epizy.com/free_avast_antivirus_pro_for_android.pdfIn PDF document text
    • https://s3.amazonaws.com/nedijowewoded/metalulatimepevazipux.pdfIn PDF document text
    • http://lofitometuzaba.epizy.com/91699430727.pdfIn PDF document text
    • https://s3.amazonaws.com/penale/c_language_objective_questions_and_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/kiremefegonar/anatomical_planes_and_sections_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/tezofuretejom/vcaa_examiners_report_literature.pdfIn PDF document text
    • http://talaxevavilur.rf.gd/lettering_templates_for_applique.pdfIn PDF document text
    • https://s3.amazonaws.com/sefepugolupalax/75371640116.pdfIn PDF document text
    • http://movutep.rf.gd/how_much_is_google_play_books_app.pdfIn PDF document text