Malicious PDF — malware analysis report

Static analysis result for SHA-256 207338bc79be61da…

MALICIOUS

PDF

80.4 KB Created: 2021-07-18 11:54:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-31
MD5: 5cd3fd6a996133e38c95d979028ad121 SHA-1: c320497ee54066e49483c6d529111951f7162032 SHA-256: 207338bc79be61da978cb6b94f46d8541edce5ef73b9565d7d1ba582246a70b0
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of an embedded URI pointing to a suspicious URL, despite its benign reputation label, suggests an attempt to redirect the user to a malicious site. The PDF structure and metadata indicate it was generated by wkhtmltopdf, which can be used to create malicious documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6016

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/LPIa9PGmDLg/uplcv?utm_term=heritage+tamil+meaning PDF link annotation