Malicious PDF — malware analysis report

Static analysis result for SHA-256 807508a255e5bd81…

MALICIOUS

PDF

58.4 KB Created: 2021-02-02 23:53:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3f6d299ab3d3f192c060e7447adf08fa SHA-1: d3b4d349a6b2c0588fd6244893caa1c586611685 SHA-256: 807508a255e5bd81585e97d1e13be24b126e9848d730d164145e1b10059eb5e8
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by multiple heuristics, including a ClamAV detection for Pdf.Phishing.Trojan. The embedded URI points to a suspicious domain, suggesting a phishing or malware distribution attempt. Although no scripts were explicitly extracted, the PDF structure and embedded URI indicate an attempt to redirect the user to a malicious site, likely for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6841

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/aws?utm_term=printable+color+worksheets+for+preschool
    • https://static.s123-cdn-static.com/uploads/4368504/normal_5fc91ad73d2bc.pdf
    • https://static.s123-cdn-static.com/uploads/4478422/normal_5ff50cfd84c4d.pdf
    • http://gufutaca5.xyz/beep_sound_mp4ols1s.pdf
    • http://bluebadgeform.com/evil_hunter_dead_zombie_survival_mod_apknt05k.pdf
    • https://cdn.sqhk.co/raxavetaletu/GuGibud/60976581675.pdf
    • https://cdn.sqhk.co/devisojop/gcJUjaQ/sausage_run_apk.pdf
    • http://trokot-shtorki.online/a_manual_for_living_epictetus_free_downloadtjyx0.pdf
    • https://cdn.sqhk.co/bavomizobe/koggiej/84797127297.pdf
    • https://cdn.sqhk.co/nesuxozajek/hb0bjjx/vujunov.pdf
    • http://feyakast.online/poemas_de_amor_gustavo_adolfo_becqueruer1t.pdf
    • http://blablablacar.online/race_car_design_derek_seward_downloadyd3zv.pdf
    • https://cdn.sqhk.co/sobexofap/Ihf3mhH/egg_inc_pc_online.pdf
    • https://static.s123-cdn-static.com/uploads/4386073/normal_5fdff2850d0fb.pdf
    • https://cdn.sqhk.co/nolovojawek/gjjd8gh/kunci_jawaban_just_draw_level_50.pdf
    • https://s3.amazonaws.com/sakaburepagase/1620879678.pdf
    • https://s3.amazonaws.com/luramamelolem/automatic_door_opening_system_ppt.pdf
    • https://s3.amazonaws.com/selivuvumepaveb/air_fryer_philips_walita_manual.pdf
    • https://s3.amazonaws.com/lanorolowu/yakuza_kiwami_2_chapter_11_guide.pdf
    • https://s3.amazonaws.com/lukepepe/myocardial_infarction_nejm.pdf