Malicious PDF — malware analysis report

Static analysis result for SHA-256 7532544479efcc70…

MALICIOUS

PDF

39.0 KB Created: 2021-08-16 19:17:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-11
MD5: 746ce6479c4691467a2f770dc8433fa8 SHA-1: 2d020d14bc090a0ed870d19a68c505e0e7d7759f SHA-256: 7532544479efcc70aa4e9eb752a837d249f554d9f18eb163561ef717593fbd6e
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ClamAV heuristic identified this PDF as a phishing trojan. The embedded URLs, although one is marked benign, suggest an attempt to redirect the user to malicious content. The PDF structure itself contains external URIs that likely lead to further malicious sites, consistent with a phishing or malware distribution scheme.

Machine Learning

  • Nyx PDF Classifier clean score 0.1434

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.vitrierbxl.be/wp-content/plugins/formcraft/file-upload/server/content/files/160a7ccada76ab---96211916455.pdf In PDF document text
    • http://fashioncenterpoint.com/wp-content/plugins/super-forms/uploads/php/files/49093ec8e689679487c18cf24b543d6c/10095956206.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=barbie+the+pearl+princess+full+movie+in+hindi+dailymotionPDF link annotation