Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e4e64d582e1f654…

MALICIOUS

PDF

51.0 KB Created: 2020-12-30 16:47:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-20
MD5: a2b5d2bb36b82ec671880a7a1c28bc5d SHA-1: 2bbf7ef6729bfb4bd8cc50a76888f17db6d5a0a9 SHA-256: 3e4e64d582e1f654922fe3640e9f946838241e861f1d270162f8c4ec42cce991
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to 'Blackbird fly chapter 1 summary'. No scripts were extracted, but the presence of external URIs and the malicious verdict indicate it likely serves as a dropper or phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6098

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/wb?keyword=blackbird%20fly%20chapter%201%20summary PDF link annotation
    • https://cdn.sqhk.co/wezopexa/fhjjghb/3763319104.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4415770/normal_5fa528e180163.pdfIn PDF document text
    • https://cdn.sqhk.co/lapitobexeva/PDIKUhg/comicsgate_is_winning.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4394068/normal_5fe854e3d6675.pdfIn PDF document text
    • https://cdn.sqhk.co/nufanusiki/hcmUPij/ratemigebu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2cfc493b-d9dc-4428-9cc8-fa7c8ba73e5f/componentes_del_espacio_geografico_naturales.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1dad3c71-f1d0-49c8-9393-4959f9395679/54165366914.pdfIn PDF document text
    • https://s3.amazonaws.com/baxekojojexusol/algebra_1_regents_august_2019_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2a537c16-6be3-4538-b1eb-e7c4d1642cbd/19041479483.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c98c7982-88d0-463d-b3c3-e6e796c31fd3/70842940280.pdfIn PDF document text