Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d204f0aa3d80ea3…

MALICIOUS

PDF

48.0 KB Created: 2021-09-10 08:13:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-12
MD5: bba29ffe08a2cd9ca06f830fccda921d SHA-1: 288040206e11256861fd54d4fdaadd0254a8e66d SHA-256: 3d204f0aa3d80ea335275330cd6759e6872dc2e5e5a730997857417849f0a38d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious content. Embedded URLs suggest an attempt to redirect the user to potentially harmful websites. While no scripts were explicitly extracted, the PDF structure and heuristic firings point towards a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8800

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hytechplus.com/userfiles/file/58294653480.pdf In PDF document text
    • https://adepotcustom.com/UploadFiles/file/20210907135102189.pdfIn PDF document text
    • http://aloisiquadri.it/userfiles/files/wovupatekoxalobedugazul.pdfIn PDF document text
    • http://salocchi.it/userfiles/files/50095194611.pdfIn PDF document text
    • http://telek-trans.hu/editor_up/zojedipIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/3vuEKuznOb8/uplcv?utm_term=sharkboy+et+lavagirl+streaming+vfPDF link annotation