Malicious PDF — malware analysis report

Static analysis result for SHA-256 56d0b1b69f741ab0…

MALICIOUS

PDF

49.6 KB Created: 2020-12-25 01:53:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ff26d8134be882c821d37c46bf2bc710 SHA-1: 87ee0085d004f2533cc27bcb8eea719e63c97a23 SHA-256: 56d0b1b69f741ab0e080b1b6dc9164bcd91329f073ca6d9beaa2a17fc0a7ca28
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file is identified as malicious by ClamAV and an ML classifier. The 'PDF_IMAGE_LURE' heuristic indicates it's an image-only document designed to trick users into clicking an embedded link, a common phishing tactic. The embedded URL points to a suspicious domain, likely serving as a lure for a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7532

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 49 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/aws?utm_term=behaviorist+theory+of+personality+pdf
    • https://cdn-cms.f-static.net/uploads/4369174/normal_5fa793f315036.pdf
    • https://uploads.strikinglycdn.com/files/afabd286-59f8-4830-abc5-a63b6549755d/82411378358.pdf
    • https://uploads.strikinglycdn.com/files/ae4145e6-fcb1-41a2-b183-3f83aca29f63/64398932639.pdf
    • https://uploads.strikinglycdn.com/files/5be4a35f-7202-4745-b1d5-97e6c3f9bdc9/empereur_lempire_du_milieu_iso.pdf
    • https://uploads.strikinglycdn.com/files/c82f638e-87f7-4120-aef3-0ce154ad8d4e/shark_simulator_3d_poki.pdf
    • https://uploads.strikinglycdn.com/files/fbdd022a-fe7f-4632-b2f3-9f31980111a7/gegiribepi.pdf
    • https://uploads.strikinglycdn.com/files/f74fcd4b-c61c-4349-8809-fec5db327154/98094116271.pdf
    • https://uploads.strikinglycdn.com/files/6157e028-502e-48b6-8738-c71b5d437ffd/5027476625.pdf
    • https://uploads.strikinglycdn.com/files/ba78a25e-22e5-4bfc-84a3-3cc88532cc26/nojod.pdf
    • https://uploads.strikinglycdn.com/files/e70c2e83-2dd9-496f-b338-3a39eff718b0/vujunidisogujutizuzuse.pdf
    • https://uploads.strikinglycdn.com/files/cebc90d3-038c-4892-acb7-3cb11da4759f/zigibugesaxogenigekejaxuz.pdf