Malicious PDF — malware analysis report

Static analysis result for SHA-256 80b366cb8f14bb2c…

MALICIOUS

PDF

58.4 KB Created: 2021-03-20 15:11:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eb0fabffeb45e36f187d056f5031533e SHA-1: bc3386042735fd09b2d0a7a9df7860bf0687b88e SHA-256: 80b366cb8f14bb2c9aa3d05c3e575dd586708cb69ec05b993abf58a7ea15d617
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a phishing or malware download site. The document body, though heavily obfuscated, suggests a lure related to 'types of red blood cells'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6079

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=types+of+red+blood+cells+pdf
    • https://cdn.sqhk.co/xubulozirod/jflfQEn/stream_american_football_games_free.pdf
    • https://cdn.sqhk.co/nebuwaxisiw/mjeJhek/sixobajagugite.pdf
    • https://wigikeketiru.weebly.com/uploads/1/3/1/4/131406435/f7c1308.pdf
    • https://nogorixarolixi.weebly.com/uploads/1/3/0/7/130740589/jibidapozoguwire.pdf
    • http://pogofefopi.22web.org/android_tv_box_apps_singapore.pdf
    • https://cdn.sqhk.co/kivipemo/yUjhOie/kidafodalatariforinoporeb.pdf
    • https://pazunorafozide.weebly.com/uploads/1/3/0/7/130776571/5995121.pdf
    • https://kazubuxupopa.weebly.com/uploads/1/3/2/6/132696048/lunuje.pdf
    • https://cdn.sqhk.co/tefupudoma/ipXhajo/3_horses_running_drawing.pdf
    • https://static.s123-cdn-static.com/uploads/4471464/normal_5fff6ea87041c.pdf
    • https://mavuzoxawajike.weebly.com/uploads/1/3/0/9/130969593/foruwigu.pdf
    • https://gaxezoxo.weebly.com/uploads/1/3/0/7/130776828/pevukuna.pdf
    • https://fotijaxak.weebly.com/uploads/1/3/4/1/134108731/492375.pdf
    • https://cdn.sqhk.co/mozoposowi/jdjfRhg/11230909919.pdf
    • https://xakediripikevul.weebly.com/uploads/1/3/4/3/134338645/1484791.pdf
    • https://cdn-cms.f-static.net/uploads/4404497/normal_60307c407cc71.pdf
    • https://uploads.strikinglycdn.com/files/3661569d-2363-4b1b-984f-3c3bcbe39d37/jukukixegodepikigun.pdf
    • https://uploads.strikinglycdn.com/files/b9cde901-2dc3-4aec-8265-c39edc413b61/1726942327.pdf
    • https://uploads.strikinglycdn.com/files/5093d210-d3c8-4e26-b34e-1da2c7e1d29e/clear_speech_4th_edition_teachers_book.pdf
    • http://zerekigukazaja.epizy.com/62795934944.pdf
    • https://uploads.strikinglycdn.com/files/4c6c4ea8-9568-4044-bfc2-65df244eb36e/how_to_answer_tell_me_about_yourself_in_a_university_interview.pdf
    • http://genuxemesusirif.rf.gd/estrategias_de_comprension_lectora_ziemax.pdf