Malicious PDF — malware analysis report

Static analysis result for SHA-256 3587759e82a5dc3f…

MALICIOUS

PDF

76.3 KB Created: 2021-03-17 00:58:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 533432a0d9c388c29481a17466d02c07 SHA-1: 61adf16fbd43bcb52617da1c4d69c3c690253e8c SHA-256: 3587759e82a5dc3f861aaef6e8826bb726a140209847155ac009285ec5e0cea7
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to a URL that appears to be part of a phishing lure, suggesting the document is designed to trick users into downloading further malicious content. The presence of multiple external URLs further supports the phishing and potential malware distribution intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8907

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/award?keyword=rococo+art+pdf
    • https://cdn.sqhk.co/kuwusetoteji/gjbie6E/94718463855.pdf
    • https://cdn.sqhk.co/guvelebul/jeLgcgi/bridge_constructor_portal_ios_free_download.pdf
    • http://webdefilmizle.com/29634605764ab70g.pdf
    • https://cdn.sqhk.co/dadirowuj/hhjiQgd/1939626244.pdf
    • https://cdn.sqhk.co/rasirise/fggqihC/star_wars_galaxy_of_heroes_game_guardian.pdf
    • https://cdn.sqhk.co/wiwuwigo/VhcThfa/foosball_tabletop_game.pdf
    • http://sy0n.icu/mapuwewimogob8chue.pdf
    • https://cdn.sqhk.co/tefozakozup/5Ughwig/rc_buggy_kits_to_build.pdf
    • https://cdn.sqhk.co/guwaloxipete/gBtppQv/tofuwuzuvuvejebo.pdf
    • https://cdn.sqhk.co/soxoxefumuv/ihpXRij/zuzifilotexe.pdf
    • https://cdn.sqhk.co/xetasenuwoji/gijmAgh/ice_cream_truck_rental_nj.pdf
    • https://cdn.sqhk.co/fomolunuvufa/9hejf0Q/followers_skyrim_se.pdf
    • http://idealslim-ordina.site/kuwasonefilanetusxxo4l.pdf
    • https://cdn.sqhk.co/dibirolinu/6sBgdij/6_simple_strategies_for_trading_forex.pdf
    • http://bluetea.space/80214718754up87v.pdf
    • http://reduslim-eu.site/98154761189bl5jd.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://lazasubesuwup.epizy.com/ccs_university_semester_exam_form_2019.pdf
    • http://fasosusa.epizy.com/amante_esposa_kate_walker.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000106d7.bin
e8ab09eb0a1c2149c0e1e2a0c170aae42cfc2bbf14df695c5c1327f8b3e7bd4f
pdf-font-stream PDF embedded font (sfnt) at offset 0x106D7 4460 bytes