Malicious PDF — malware analysis report

Static analysis result for SHA-256 07edd43b14cce8f6…

MALICIOUS

PDF

58.4 KB Created: 2021-02-13 13:09:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: b58683b7c55f032857aca290531239ae SHA-1: c425c572209460a41f5c018e01582ecfb43cfc08 SHA-256: 07edd43b14cce8f6398a36cad352c8f7548a73c92cda9b41a2a1a7748488d994
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9894

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/aws?utm_term=lux+build+proguides PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4387817/normal_5fd76f51c5cb6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4486051/normal_601458c8f3b1b.pdfIn PDF document text
    • https://mufobaxepomek.weebly.com/uploads/1/3/4/8/134866816/ec54e536e19835.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4450635/normal_60016b0a58ca1.pdfIn PDF document text
    • https://kexiwiwimibip.weebly.com/uploads/1/3/1/3/131379584/tedugajanonasepu.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4424025/normal_60176b80d1981.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4458826/normal_5ff4964043e11.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4485015/normal_60073f3498006.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4388158/normal_60094c454057e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384822/normal_5feaee83574ab.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4402712/normal_60172b16e776c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4426813/normal_5fee8f8a1a7e0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4449419/normal_60010eefbec74.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4450870/normal_600256707a097.pdfIn PDF document text
    • https://s3.amazonaws.com/gedexim/tamil_melody_songs_kuttyweb.pdfIn PDF document text
    • https://s3.amazonaws.com/rawesaragegugar/page-_break-_inside_avoid_not_working_mpdf.pdfIn PDF document text
    • https://s3.amazonaws.com/fogibi/lonamilezuja.pdfIn PDF document text
    • https://s3.amazonaws.com/bifadiwuwileji/video_lagu_bruno_mars_grenade.pdfIn PDF document text
    • https://s3.amazonaws.com/pazerogasarinu/lopigukiguge.pdfIn PDF document text