Malicious PDF — malware analysis report

Static analysis result for SHA-256 8624aa613cc0ae3b…

MALICIOUS

PDF

50.3 KB Created: 2021-04-05 02:47:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d5965cf0d3cefcdb2b82c7c21e5d646c SHA-1: 53e633a2bf54761fc5228aeef65170454036dddb SHA-256: 8624aa613cc0ae3ba8b3dd19430c9ba40b4ef670992e973e255657715f3cb99f
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as a phishing lure due to its image-heavy nature and a single clickable action. It contains an embedded URL that likely leads to malicious content or a phishing page. The ClamAV detection and ML classifier further support its malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7154

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 50 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/award?keyword=anexo+6+oaci+pdf
    • https://cdn-cms.f-static.net/uploads/4412159/normal_6031074598839.pdf
    • https://cdn-cms.f-static.net/uploads/4447669/normal_6034097e9139a.pdf
    • https://cdn-cms.f-static.net/uploads/4460076/normal_5fd91700ba3aa.pdf
    • https://static.s123-cdn-static.com/uploads/4423154/normal_60018414f111a.pdf
    • https://cdn-cms.f-static.net/uploads/4367644/normal_6030939876f8d.pdf
    • https://static.s123-cdn-static.com/uploads/4446512/normal_6005ec976de55.pdf
    • http://sixawuragime.iblogger.org/cambridge_english_placement_tests.pdf
    • https://cdn-cms.f-static.net/uploads/4418566/normal_603fd9db212e4.pdf
    • https://static.s123-cdn-static.com/uploads/4473064/normal_5fc8a562dd5b4.pdf
    • http://gakajunefuvefo.iblogger.org/60983237553.pdf
    • https://cdn-cms.f-static.net/uploads/4386354/normal_6059cb0769f44.pdf
    • http://tinuliv.22web.org/murubenuvirufizokapesakuj.pdf
    • https://f33d1b56-f518-462b-b61f-c1b5c1ba661c.filesusr.com/ugd/1c44ce_48652365104046b69e08077fb4aa91c1.pdf?index=true
    • https://dedb376b-efc3-4528-ac10-fc65d12f866c.filesusr.com/ugd/5f6074_f55d6aedb6554f1298ea794b2da51e8a.pdf?index=true
    • http://riwexakax.epizy.com/befuxakesiledipakuj.pdf
    • http://pisisagul.epizy.com/feserubumilokaxixonavideg.pdf
    • https://3c86e5df-9a55-47dd-9d5b-c207b25ec6cd.filesusr.com/ugd/72bf36_a12c43d78d2b40bebdc8186fb7cee09a.pdf?index=true
    • http://nofefebevuxojaf.epizy.com/90391280677.pdf
    • http://zefobik.epizy.com/43995893721.pdf
    • https://s3.amazonaws.com/lupuvogotog/psp_emulator_android_gold.pdf
    • https://s3.amazonaws.com/julexekubaj/rifufixoxajuloputipixaniv.pdf
    • https://s3.amazonaws.com/jirebonudur/how_to_use_a_bissell_little_green_cleaner.pdf
    • http://junedujivoxoz.epizy.com/camden_secondary_school_application_form.pdf
    • http://duxuvogavibu.epizy.com/gce_o_level_biology_notes.pdf
    • https://6c8027e1-9878-41b3-a9ef-32ba2b6bcd02.filesusr.com/ugd/185811_36d1f88a92344f3eb2ff1b98a42db167.pdf?index=true
    • https://535f918c-e50e-4760-9dbe-4b22a9cc1357.filesusr.com/ugd/65883d_a094b57b1d9e4ad2b3369f972e50be69.pdf?index=true
    • https://s3.amazonaws.com/fixararololu/82720606482.pdf
    • https://s3.amazonaws.com/vebogotexaf/ctr_nitro_fueled_time_trial_guide.pdf