Malicious PDF — malware analysis report

Static analysis result for SHA-256 546640eae7bcb467…

MALICIOUS

PDF

50.6 KB Created: 2021-02-04 08:33:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 147db797c6f2a0bbd56c35c90fa1d21c SHA-1: 19b3d53224315a79f9c5f7f1054ead899bb20fad SHA-256: 546640eae7bcb4671f6d71cafb17ed72a6d1f84e5c216f22f346dfd7e9254887
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF that contains an external URI pointing to a URL that appears to be a lure for downloading a driver, but is likely a phishing or malware distribution site. ClamAV and ML classifiers also flagged this PDF as malicious, specifically as a phishing trojan. The presence of embedded URLs and the nature of the heuristics suggest this document is part of a phishing campaign aiming to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7362

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/aws?utm_term=bixolon+srp+350+pg+driver PDF link annotation
    • http://all-casino.xyz/positive_affirmations_worksheete8m4s.pdfIn PDF document text
    • http://shoes-storie.club/acting_first_six_lessonscoslo.pdfIn PDF document text
    • https://cdn.sqhk.co/nulusezitelo/jaCiphi/honor_10_lite_app_store.pdfIn PDF document text
    • http://talezoruvaje.iblogger.org/evaluating_variable_expressions_worksheet.pdfIn PDF document text
    • https://cdn.sqhk.co/zapajugadira/gjkjdje/word_sauce_word_connect_puzzle_answers.pdfIn PDF document text
    • https://cdn.sqhk.co/vixukose/ig4LhlM/exogenous_vs_endogenous_variables.pdfIn PDF document text
    • https://cdn.sqhk.co/padixemugex/jjbia1M/18756951081.pdfIn PDF document text
    • https://cdn.sqhk.co/nosamese/gg6iiWk/83843631722.pdfIn PDF document text
    • https://cdn.sqhk.co/lazodadevab/bT4iigd/ringtones_for_android_free_download.pdfIn PDF document text
    • http://pink-echo.club/bollywood_ringtones_instrumentalx4mxe.pdfIn PDF document text
    • https://s3.amazonaws.com/lerezazo/47485281194.pdfIn PDF document text
    • https://s3.amazonaws.com/banula/jerinos.pdfIn PDF document text
    • https://s3.amazonaws.com/fulosobezur/dababomunezigalinu.pdfIn PDF document text
    • http://zijikekiz.epizy.com/25759951975.pdfIn PDF document text
    • https://s3.amazonaws.com/vapite/acdc_drum_sheet_music_book.pdfIn PDF document text
    • https://s3.amazonaws.com/biwubeleba/zuvizolasovexedinodilij.pdfIn PDF document text