Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e1c11057b37bc10…

MALICIOUS

PDF

42.8 KB Created: 2021-09-14 10:44:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-11
MD5: 0aa76d65ccc22dc596be5ecb561edb7a SHA-1: 7d14444e83b80eb81d166798e2d538477d8153db SHA-256: 3e1c11057b37bc10ef6cbf755122a72f11ec954c4f1c4ecaa3ff617f04ee46e3
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ClamAV heuristic identified this PDF as a phishing trojan. The PDF contains embedded URIs that point to external websites, likely for phishing purposes. While no scripts were explicitly extracted, the presence of embedded URIs and the ClamAV detection strongly suggest a phishing attack vector, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4239

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://villaturri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613df25c554ea---27603019512.pdf In PDF document text
    • https://simondaulte.com/ckfinder/userfiles/files/sitiwenirilik.pdfIn PDF document text
    • https://f2h63c2.ip4secure.net/upload/files/zalinixewiveravokevu.pdfIn PDF document text
    • http://euskararenginkana.eus/files/galeria/files/vosesakidatapu.pdfIn PDF document text
    • https://cbolean.com/wp-content/plugins/super-forms/uploads/php/files/63bcd30d1cc052bc161e3d461fdb8ad9/foxufigituxonewiw.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=lean+male+bodyPDF link annotation