Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d56110a73ffb5de…

MALICIOUS

PDF

54.0 KB Created: 2021-09-16 16:03:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-12
MD5: 0868dc76c064a6a75e1d395233f19299 SHA-1: 9bffdd9bfdf7f7762fef89207f28edb00114a3a4 SHA-256: 2d56110a73ffb5deb467a30af8b1d1ea207266ce24d5d4970ff9f65f8de10cac
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as a phishing trojan by ClamAV. It contains an embedded URI pointing to 'pistant.ru', which is likely used to redirect users to malicious content. The PDF structure and embedded URLs suggest an attempt to deliver a malicious payload or conduct phishing activities.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4874

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pistant.ru/uplcv?utm_term=mortal+kombat+movie+kung+lao PDF link annotation
    • https://frennphotography.com/wp-content/plugins/formcraft/file-upload/server/content/files/16142f032d2741---kowajaxerolagadavofekubak.pdfIn PDF document text
    • https://korvioinfotech.com/ckfinder/userfiles/files/filunujofegafoso.pdfIn PDF document text