Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c442f489f0e22e5…

MALICIOUS

PDF

66.6 KB Created: 2021-05-10 03:19:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: b19fa1a02e866aa70e761fd79d61b5be SHA-1: 917a5203a693b9eb47ce46b74842a2321b369081 SHA-256: 6c442f489f0e22e59191819276ca35b0907d9ea30464bb21597da89bc6254276
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5247

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=where+to+buy+pre+cooked+christmas+dinner PDF link annotation
    • http://profer-opt.ru/294175659120bkgx.pdfIn PDF document text
    • http://reduslim-italiaoficial.site/davefiforitemilosuj95bk3.pdfIn PDF document text
    • http://universityru.fun/topamibiwekabevazejisaw5pec7.pdfIn PDF document text
    • http://skidki-day.store/nagolabozugopakom4k1o.pdfIn PDF document text
    • http://lixorajepidil.mygamesonline.org/download_logarithm_and_antilogarithm_table.pdfIn PDF document text
    • https://cdn.sqhk.co/kepozote/glSifgY/select_55_beer_nutrition_information.pdfIn PDF document text
    • http://futup.ru/fake_call_simulator1vats.pdfIn PDF document text
    • https://cdn.sqhk.co/sebutarukaw/gfKEvhj/58237267450.pdfIn PDF document text
    • http://helpforteam.com/833714679e0bnw.pdfIn PDF document text
    • http://habirovradik.ru/fedomokajagikolom7u5e3.pdfIn PDF document text
    • http://xagevogewa.medianewsonline.com/enlace_ionico_libro.pdfIn PDF document text
    • https://cdn.sqhk.co/zogobadakedu/fHcjfKh/59346362264.pdfIn PDF document text
    • http://ighelpcenter.xyz/does_my_modem_support_5ghzjgel4.pdfIn PDF document text
    • http://mosuxuvemuzuwex.mywebcommunity.org/63805990265.pdfIn PDF document text
    • http://jopagozopive.medianewsonline.com/gagoxokedomawopop.pdfIn PDF document text
    • http://xupokaxe.medianewsonline.com/solid_waste_management_project_proposal.pdfIn PDF document text
    • http://boomua.site/ximuvijetunidejobhqpl1.pdfIn PDF document text
    • https://s3.amazonaws.com/ratixifo/zedirabudikasetu.pdfIn PDF document text
    • https://s3.amazonaws.com/rutufokedizon/gravimetric_determination_of_chloride_lab_report.pdfIn PDF document text
    • https://s3.amazonaws.com/xedewofuretujo/92948193103.pdfIn PDF document text
    • https://s3.amazonaws.com/lemefofutomapox/xutovozukufegibe.pdfIn PDF document text
    • https://s3.amazonaws.com/fevobelijogal/43118151386.pdfIn PDF document text
    • https://s3.amazonaws.com/xuvamuba/gelelojapoxoxore.pdfIn PDF document text
    • https://s3.amazonaws.com/dibedamoka/is_cosrx_salicylic_acid_cleanser_good_for_fungal_acne.pdfIn PDF document text
    • https://s3.amazonaws.com/xisakazelelinim/46453183588.pdfIn PDF document text