Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b63915e36e66d25…

MALICIOUS

PDF

46.2 KB Created: 2021-02-27 12:15:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 7534fcbca592683c4849345e4618b208 SHA-1: 5854e11744b7cddcf119a80f1f4d4eba9dc1257c SHA-256: 4b63915e36e66d25ffbf89ef41836bd2ee4d6f9a0db781f630fcd688b3124ab3
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains an embedded URL pointing to a suspicious domain, likely intended to trick the user into clicking it. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. Although no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest an attempt to redirect the user to a malicious site for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8301

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/award?keyword=how+often+does+league+of+legends+patch PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4369496/normal_5fc8d163b6fdd.pdfIn PDF document text
    • https://radoxawema.weebly.com/uploads/1/3/0/7/130738714/mejof-lavupoliwuture-mejalilalaj.pdfIn PDF document text
    • https://worojipe.weebly.com/uploads/1/3/1/3/131382243/f97249c322510.pdfIn PDF document text
    • http://kejefutipetube.epizy.com/best_android_version_for_s7_edge.pdfIn PDF document text
    • http://popeladidet.epizy.com/kasupo.pdfIn PDF document text
    • http://zelobiliteriwe.rf.gd/heart_shaped_stethoscope_vector_free.pdfIn PDF document text