Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b9c15f6f62edc59…

MALICIOUS

PDF

41.5 KB Created: 2021-09-03 11:23:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-16
MD5: b49642edcb7fa7488430fcfc730fa48e SHA-1: afc366d04c20ccbeb82463bd0c6bc3fccbc358c5 SHA-256: 1b9c15f6f62edc59aa4510510e9b94cd66038cd089c1e05d38ef59820172c472
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as a phishing trojan by ClamAV. It contains multiple embedded URLs, one of which is disguised as educational material, likely to trick users into downloading further malicious content. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.2957

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.mobytec.com.br/mobytec/wp-content/plugins/formcraft/file-upload/server/content/files/160f3c14543639---veparulamosajofuvezila.pdf In PDF document text
    • http://er-trans.com/img/produkty/files/75508359227.pdfIn PDF document text
    • https://skl.deindrukdemo.nl/upload/files/96727771819.pdfIn PDF document text
    • https://www.teppiche-waschen-hamburg.de/wp-content/plugins/formcraft/file-upload/server/content/files/16091898789084---zuzuropixemasazisen.pdfIn PDF document text
    • https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/1610e6ff2a6d4f---muniraguvonugalu.pdfIn PDF document text
    • http://solarexperten.ch/fckeditor/editor/images/file/99298170334.pdfIn PDF document text
    • http://limobebe.com/userfiles/files/nutefok.pdfIn PDF document text
    • https://nhakhoaanphuoc.vn/uploads/files/zerofalolovejilosijirif.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1KS0DP0cxss/uplcv?utm_term=grade+9+mathematics+question+papers+pdfPDF link annotation