Malicious PDF — malware analysis report

Static analysis result for SHA-256 7835430a364eb2d6…

MALICIOUS

PDF

37.3 KB Created: 2021-09-30 22:04:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-22
MD5: b23c3be5f1011eed2c024e33fa2c2136 SHA-1: e407d6a983e794510b4dea0d67e746147bb0fd5b SHA-256: 7835430a364eb2d6efcf7c0f052b4ec9cbd2c7278013430d2d6fff3109689570
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file is identified as malicious by ClamAV and an ML classifier, exhibiting characteristics of a phishing lure. The 'PDF_IMAGE_LURE' heuristic indicates it contains an image designed to trick users into clicking an embedded URI. The primary URI, https://smidgel.ru/uplcv?utm_term=cheapest+smartphone+2020+philippines, likely serves as the initial point of contact for a phishing campaign or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6333

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 37 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://smidgel.ru/uplcv?utm_term=cheapest+smartphone+2020+philippines PDF link annotation
    • http://doorsatyrau.com/ckfinder/userfiles/files/34081834961.pdfIn PDF document text
    • http://otvorene-srdce.sk/userfiles/file/jidawovibuveladered.pdfIn PDF document text
    • https://gkia.org/kingkong/userfiles/files/47527848612.pdfIn PDF document text
    • https://sandp-engineering.com/ckfinder/userfiles/files/8967013763.pdfIn PDF document text
    • http://dabien.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/16135264c47441---woririsatogajaloxinerado.pdfIn PDF document text
    • https://aihr-iadh.org/uploads/FCK_files/file/5855538568.pdfIn PDF document text
    • http://formacio.fic.cat/uploads/file/xupog.pdfIn PDF document text
    • http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/9508cf3b38d0f8451d0deb9d2287ec5f/midosadu.pdfIn PDF document text