Malicious PDF — malware analysis report

Static analysis result for SHA-256 074b5d2b6b7343ee…

MALICIOUS

PDF

50.6 KB Created: 2020-12-04 14:13:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f8202e4089effd09b309585f515f168b SHA-1: 8fddce4fd3272f2906a86d7572367f78add3cfb8 SHA-256: 074b5d2b6b7343ee78596f1e22047cb5ae7d8455aead0bc855506edbb01b740d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains an embedded URI pointing to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The document body, though heavily obfuscated, appears to be a lure related to medical guidelines. No scripts were extracted, but the presence of an external URI and the ML classification strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7800

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/aws?utm_term=traumatic+intracerebral+hemorrhage+guidelines
    • https://cdn-cms.f-static.net/uploads/4422876/normal_5f9bd1457c363.pdf
    • https://uploads.strikinglycdn.com/files/c1bb6ddc-48d4-4ce1-a9a7-8c345c19149b/2739878948.pdf
    • https://s3.amazonaws.com/fomudebipefasu/85830068240.pdf
    • https://static1.squarespace.com/static/5fc1d2da12facd59ceb37db7/t/5fc4be6a4e98326c02a6ee65/1606729323980/14160587981.pdf
    • https://uploads.strikinglycdn.com/files/4c1ea934-2267-432b-b793-803573b1b5f9/83665234510.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbcfec7b474932ca267efb3/1606221514256/13845342526.pdf
    • https://static1.squarespace.com/static/5fc65c3a24b06a7eb324d99c/t/5fc829c8ec83506b046f5d19/1606953418187/79585393852.pdf
    • https://uploads.strikinglycdn.com/files/b0953436-0611-4ca5-9cb3-eeb58a04b45e/stages_of_revolution_french.pdf
    • https://static1.squarespace.com/static/5fc0dd745bcb0228a2824d01/t/5fc649e73485235c869cd6bb/1606830567767/78802079083.pdf
    • https://uploads.strikinglycdn.com/files/425a4416-a3c5-41f6-a5ee-ed34ed8391ba/only_hearts_club_wiki.pdf
    • https://uploads.strikinglycdn.com/files/4c03aed6-3a28-4762-a956-a22abd3a2fc7/livro_em_busca_do_tempo_perdido_obra_completa.pdf
    • https://uploads.strikinglycdn.com/files/90203aa3-d60f-426f-8e13-bc9b9f771487/devovigipugogenalowigiki.pdf