Malicious PDF — malware analysis report

Static analysis result for SHA-256 42a6715e5e988287…

MALICIOUS

PDF

67.6 KB Created: 2021-05-03 01:55:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 98267fd00bf3965015659123caec9547 SHA-1: 88aca21c10c84b59b413e70ba458c02615eed101 SHA-256: 42a6715e5e9882872adc5551f70cc329d6306ce0fa1b8f2afba7290972c7ce45
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file is identified as malicious by ClamAV and an ML classifier. It employs an image-only lure, a common tactic for phishing or malware distribution. The embedded URL points to a suspicious domain, likely serving as a landing page for the attack. No scripts were extracted, but the PDF structure itself suggests a malicious intent to redirect the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8813

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 67 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/strik?utm_term=cuisinart+ice-30+instructions
    • http://xomerisupudegop.medianewsonline.com/lars_brownworth.pdf
    • http://xevijuwidenuxet.mypressonline.com/allaitement_maternel_exclusif_dans_le_monde.pdf
    • http://mobufuwiwid.medianewsonline.com/tiny_homes_plans_canada.pdf
    • http://zonizubiro.getenjoyment.net/69827265391.pdf
    • http://repair-monokoles.ru/vizojlyy2h.pdf
    • http://academic-club.ru/kowimofoi09ol.pdf
    • http://changepass.online/ukulele_strumming_patterns_4_4d4fg6.pdf
    • http://sweetygirl.club/how_to_cure_chigger_bites3vez4.pdf
    • https://xovesoxak.weebly.com/uploads/1/3/0/8/130813458/xekeraruwa.pdf
    • https://mejonozawus.weebly.com/uploads/1/3/4/0/134016798/9494104.pdf
    • http://summ-green.fun/zivekikazogujexibozukelok2sxm5.pdf
    • http://faleferesevo.onlinewebshop.net/adjective_clause_reduction.pdf
    • http://zenakezogutomu.onlinewebshop.net/putadesomages.pdf
    • https://s3.amazonaws.com/vunizi/define_development_planning.pdf
    • https://s3.amazonaws.com/jesidofefe/gadatupimitonunazedejoru.pdf
    • http://sajulugebimisu.myartsonline.com/16263634735.pdf
    • http://teluroluxeterez.myartsonline.com/nibejopinudixexovikoxoma.pdf
    • https://s3.amazonaws.com/rutufokedizon/august_2019_calendar_template_excel.pdf
    • http://xomapagovujux.atwebpages.com/intermezzo_cavalleria_rusticana_piano_sheet_music.pdf
    • http://gegetebipa.atwebpages.com/american_gods_neil_gaiman_franais.pdf