Malicious PDF — malware analysis report

Static analysis result for SHA-256 80901b380f07bff0…

MALICIOUS

PDF

39.6 KB Created: 2021-10-04 13:51:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-24
MD5: cded4f1453458714714594d6731742c7 SHA-1: 8fd36c4adabe5d6676de60e206b0aa8ddb69782f SHA-256: 80901b380f07bff0e7a6e123155bc75d921a20944218da4e85153acaf45d690a
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a phishing and trojan detection. It contains an embedded URI pointing to 'pistant.ru', which is likely used to redirect users to a malicious site. The presence of multiple other suspicious URLs further supports a phishing or malware distribution intent. No scripts were extracted, but the PDF structure and embedded URIs are indicative of a phishing lure.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3902

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pistant.ru/uplcv?utm_term=how+to+remove+marker+from+jeans PDF link annotation
    • http://rucodelniza.ru/userfiles/file/pitula.pdfIn PDF document text
    • http://www.cpiequipos.com/assets/images/user_files/files/33130591607.pdfIn PDF document text
    • http://pokorny-podlahy.cz/UserFiles/File/muzuletipetaporirezu.pdfIn PDF document text
    • http://naturallabs.de/userfiles/file/89450117321.pdfIn PDF document text
    • http://doktor-okonski.pl/uploadimg/file/38906143160.pdfIn PDF document text