Malicious PDF — malware analysis report

Static analysis result for SHA-256 24c269abc1e45705…

MALICIOUS

PDF

38.0 KB Created: 2021-04-01 01:57:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: be8bda1cb7acdc72eee329e847791e96 SHA-1: a24060dedfe1f3ffec379b26ce9ad06e3d3e0890 SHA-256: 24c269abc1e45705ff81eaad428cf4c82afb659d4e1f97f29a92ecd2947a8603
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as a phishing lure due to its small size and image-heavy content, typical of a screenshot hiding a clickable link. The embedded URL 'https://baarspo.ru/award?keyword=watermark+maker+pdf' directly supports this, indicating a phishing attempt to redirect the user. ClamAV and ML classifiers also flagged this PDF as malicious, reinforcing the phishing conclusion.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6976

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 38 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/award?keyword=watermark+maker+pdf
    • http://vemonubamupol.iblogger.org/south_movie_video_songs.pdf
    • https://cdn-cms.f-static.net/uploads/4427781/normal_6040de83221cc.pdf
    • http://renubinivudeti.epizy.com/2108071006.pdf
    • https://203e7bc3-08d7-4ecc-a8df-f797e0d4a079.filesusr.com/ugd/d4579c_34297d558c51437f86ba44152afb27b6.pdf?index=true
    • http://limoxukuk.atwebpages.com/how_to_test_a_hydraulic_pressure_sensor.pdf
    • http://pusevim.epizy.com/old_gulabi_aankhen_song_pagalworld.pdf
    • http://zomudipanosu.epizy.com/is_frm_level_1_difficult.pdf
    • https://cee4a208-09ac-40e0-983f-4c2cc776acbe.filesusr.com/ugd/5ed537_8d837d8686d74d4fbd3d95030583af12.pdf?index=true
    • https://cf4de027-7369-46c2-bf93-d69cabef2b5e.filesusr.com/ugd/868b90_c0500a086cee40549c03b898175efc53.pdf?index=true