Malicious PDF — malware analysis report

Static analysis result for SHA-256 83c886966bc13e39…

MALICIOUS

PDF

45.4 KB Created: 2021-09-22 13:19:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-31
MD5: b7ea1d6b9fc9fb6b5d3ed7f55d2d6af4 SHA-1: 6a398d3c1db275bad266c2e15a0c063f3f15707e SHA-256: 83c886966bc13e39b9f7c967a4d0fd7cb8e52b990f3b2f28b8d2b0d903c09e8a
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as a malicious PDF by ClamAV and an ML classifier, indicating it's designed to be harmful. Embedded JavaScript and external URIs suggest an attempt to download and execute additional malicious content, likely as part of a phishing campaign. The presence of multiple unknown-reputation PDF URLs further supports the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8074

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pazzo.jp/js/upload/files/gunomotuzezofiduze.pdf In PDF document text
    • http://hong-tour.com/FileData/ckfinder/files/20210902_680FC7E4FD2DDC53.pdfIn PDF document text
    • https://www.wizzfizz.com.au/application/third_party/ckfinder/userfiles/files/vejobigebapix.pdfIn PDF document text
    • https://rajnnuhiddje.se/userfiles/file/41071904191.pdfIn PDF document text
    • http://es-umzuege-transporte.de/wp-content/plugins/super-forms/uploads/php/files/d085feadb086d53e7783c95cf2b3c945/nusexurarimuxarekep.pdfIn PDF document text
    • http://hai-bi.com/uploads/files/202109101231491821.pdfIn PDF document text
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=the+neverending+story+1984+watch+online+freePDF link annotation