Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a36d97d35c5a12b…

MALICIOUS

PDF

66.8 KB Created: 2021-03-25 16:05:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bc456889b935d09e15fcbb4763b02583 SHA-1: 9cbaf21b18d7be8de5475adedc0df0da06227064 SHA-256: 2a36d97d35c5a12bf907043dc258b16596187faa5045cea6dd261c78701e6d06
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains an embedded URI that directs users to a URL associated with phishing. ClamAV and ML heuristics also flagged this file as malicious, indicating it is likely a phishing lure designed to trick users into visiting a malicious website. The presence of embedded URLs and the phishing detection strongly suggest an attempt to deliver a malicious payload or steal credentials.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7571

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/award?keyword=dermatitis+atopica+en+ni%25C3%25B1os+pdf
    • https://cdn.sqhk.co/laxegipo/diijiid/zutagiruvolo.pdf
    • http://gunekagafa.22web.org/pagemaker_to_ms_word_converter_online_free.pdf
    • https://cdn-cms.f-static.net/uploads/4458163/normal_601480ab28b8b.pdf
    • https://cdn-cms.f-static.net/uploads/4490949/normal_602f51f6a6f71.pdf
    • http://domutobol.22web.org/carbetocina_efectos_adversos.pdf
    • http://gatofupimekow.mywebcommunity.org/academic_writing_and_presentation_skills.pdf
    • http://susasami.22web.org/vosenexeramaz.pdf
    • https://cdn.sqhk.co/wekaradukuve/a6KCA1P/asus_outs_rog_crosshair_viii_dark_hero.pdf
    • https://cdn.sqhk.co/jevamivuvugi/Wihjbcr/59389891982.pdf
    • http://felulofija.22web.org/90097255088.pdf
    • http://vosalax.22web.org/23715242366.pdf
    • https://static.s123-cdn-static.com/uploads/4379731/normal_5fcd576879352.pdf
    • https://cdn.sqhk.co/nulegudup/IGjcU0q/apple_music_infinite_loop.pdf
    • http://vesedakowata.onlinewebshop.net/how_to_adjust_temperature_on_a_rheem_hot_water_heater.pdf
    • https://601bead5-a720-4f65-98db-62fe2a42cb91.filesusr.com/ugd/0e52b4_a2c1f6c813a14c849d4e0813e40449ad.pdf?index=true
    • https://s3.amazonaws.com/zonebon/capitalization_worksheets_printable.pdf
    • https://305aa2e3-e1d2-413d-aa2e-f1bb83d03ded.filesusr.com/ugd/92ee2b_3d75deec72d340038ba5cdcc4d458e8f.pdf?index=true
    • https://s3.amazonaws.com/mefonevimimix/daritewinevuxazonoki.pdf