Malicious PDF — malware analysis report

Static analysis result for SHA-256 81541cfb53bd800e…

MALICIOUS

PDF

51.6 KB Created: 2021-05-31 23:49:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 533f1e39d834626bb408424f58791b7a SHA-1: 3806f0d295afeddc432c765899d6b3cda001e13b SHA-256: 81541cfb53bd800ef29628fd29457c4eb757bae850cdfe7bf599a3f5f0d275b9
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7468

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://garglob.ru/pbw?utm_term=manual+istorie+clasa+4+semestrul+2+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4459036/normal_6053014384019.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4388280/normal_5ff47d6c798d1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475730/normal_5fd84401bdf8c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4492871/normal_601264094a715.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370309/normal_5fd9bf252c2c3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4481821/normal_5fe34d8b4058f.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4380705/normal_5fec0ce987883.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/41554eb6-6b57-48c4-9bff-f5fdec08223a/sharp_atomic_clock_customer_service.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/269a8536-3392-4d31-acb6-1668a5b473b4/kunoxu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/74393c1f-b92d-41c7-8374-84aa771bc9b4/sun_joe_spx3000_review.pdfIn PDF document text
    • http://wamotarirup.pbworks.com/f/gloud_games_pro_hack_apk_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3f92579f-5cbb-45f7-b453-af19d75ef7fd/24550957029.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/13926c2b-37ce-4a86-9625-a8e5d8263206/41978543264.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/83dcacd2-601b-4a6e-bebf-a05cea3feaa3/turtle_beach_x42_xbox_one_pairing.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/04e24bc0-5308-4993-b5f3-a82e76f34a9a/lexupafap.pdfIn PDF document text
    • http://bovojigu.pbworks.com/w/file/fetch/144424566/mamalufatamazumuzano.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a34fba55-2169-4270-a9e7-9e1f37f1e546/femexivexodok.pdfIn PDF document text
    • http://wemekojezum.pbworks.com/f/54437082311.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/286d3e27-48bd-40ca-a54a-a07b246b8e6f/rodimajapibejafe.pdfIn PDF document text
    • http://funinupun.pbworks.com/w/file/fetch/144419007/12417465386.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d4eed0e0-8496-4659-8600-c8a9342c2e93/18884013252.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0ac4fe18-68b5-4355-b458-53c4777039b2/74304730035.pdfIn PDF document text