Malicious PDF — malware analysis report

Static analysis result for SHA-256 17394807ca9fa7b7…

MALICIOUS

PDF

50.3 KB Created: 2021-01-01 19:09:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 628bcf3e9916d7555cfebfd7daaf9bd7 SHA-1: 2ddd3c1cfb3ebe519f099a5de1ec77348a35fca8 SHA-256: 17394807ca9fa7b7b974ee3484774fb39e3b4aff240badffa5da7b96783bde35
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as an image-only lure, typical for phishing attacks, containing a single clickable link. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URL likely serves as the initial point of contact for a phishing campaign or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7011

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 50 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=dreamcage+escape+level+8
    • https://cdn-cms.f-static.net/uploads/4367296/normal_5f98633f646ec.pdf
    • https://cdn-cms.f-static.net/uploads/4387924/normal_5f9c3a26c2a97.pdf
    • https://uploads.strikinglycdn.com/files/7c512385-974e-4ad8-8717-31c0dc9e568f/troy_battle_sights_tritium.pdf
    • https://uploads.strikinglycdn.com/files/286a3f74-b65c-4e8b-a34a-da4d06a4bc92/feranedolojufe.pdf
    • https://uploads.strikinglycdn.com/files/a0ec395b-638e-4323-a966-2542f0293334/64702885882.pdf
    • https://s3.amazonaws.com/bulozor/jodi_picoult_my_sister_s_keeper.pdf
    • https://uploads.strikinglycdn.com/files/139381b9-6066-41a9-91cc-9bd64fd5255e/quickbooks_instructions.pdf
    • https://s3.amazonaws.com/pafiganovavi/injury_report_form_word.pdf
    • https://uploads.strikinglycdn.com/files/5b67aa93-0b65-47ab-809e-7bc4e0d1110c/knowledge_issues_examples.pdf
    • https://s3.amazonaws.com/lusegokaves/tukogokufi.pdf
    • https://s3.amazonaws.com/kisagoz/lulig.pdf
    • https://s3.amazonaws.com/bufipevuril/36196749867.pdf
    • https://s3.amazonaws.com/vidadaviwal/professional_bakery_business_card_template.pdf
    • https://uploads.strikinglycdn.com/files/48e71439-e2e4-4097-99f6-0b904e4bed00/66310106794.pdf