Malicious PDF — malware analysis report

Static analysis result for SHA-256 3cffc9e4f1d490bd…

MALICIOUS

PDF

101.6 KB Created: 2020-12-17 17:48:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 46eab506442962adb3d32fd655333af4 SHA-1: b0f417a516987e995e89a04aab2842f66e6f02bf SHA-256: 3cffc9e4f1d490bdffebc9a16409d7992a56602fa7f057b0ff0ec0ae9301e7bf
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains a malicious URL, identified by the PDF_URI heuristic and confirmed by ClamAV detection. The document body, though heavily obfuscated, suggests a lure related to 'guidelines for vertebral osteomyelitis'. The presence of an embedded malicious URL indicates an attempt to redirect the user to a potentially harmful site, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9387

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/aws?utm_term=idsa+guidelines+for+vertebral+osteomyelitis
    • https://s3.amazonaws.com/fokapikow/mathematics_worksheets_for_grade_3.pdf
    • https://s3.amazonaws.com/wunojipu/watch_fast_and_furious_6_full_movie_online.pdf
    • https://uploads.strikinglycdn.com/files/991bdaa8-64fe-4c0e-92e2-fff94922c9bb/electric_post_driver.pdf
    • https://static1.squarespace.com/static/5fc1a18fea4a794d564a4325/t/5fc53c7df8cdb769c68e0415/1606761598363/capricorn_man_cancer_woman_love.pdf
    • https://uploads.strikinglycdn.com/files/1109d0b2-920b-40a7-af20-7740bd506512/physics_for_scientist_and_engineers.pdf
    • https://s3.amazonaws.com/jivagajamav/zunidojozufunogatomek.pdf
    • https://static1.squarespace.com/static/5fc6e8e404a8c57c14871e0c/t/5fd6dc69034a586a4f561caf/1607916650341/vebejaganos.pdf
    • https://uploads.strikinglycdn.com/files/140489c6-5bbf-46e9-a00c-210821b4827c/14842078404.pdf
    • https://s3.amazonaws.com/remufuzu/rokagodutofa.pdf
    • https://static1.squarespace.com/static/5fc0d2f2d26ff1194f734ddd/t/5fc2e23e173fb5383b030423/1606607422835/xaruvulezarisimozux.pdf
    • https://static1.squarespace.com/static/5fc117e49955c744b53cb0dd/t/5fc3de473570fb44d179cf4d/1606671944928/30_x_20_frame_gold.pdf
    • https://s3.amazonaws.com/safago/40062798631.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5e2ceaf37e3b64935216/1606377004771/tudaguxotedope.pdf
    • https://s3.amazonaws.com/xirixepo/77285330909.pdf
    • https://s3.amazonaws.com/lakujusitejojet/ledger_report_format_in_tally.pdf