Malicious PDF — malware analysis report

Static analysis result for SHA-256 8adc7286cf4b7f97…

MALICIOUS

PDF

79.7 KB Created: 2021-06-25 01:51:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-04
MD5: 73c7792a479a7533ce4e9095ebede44c SHA-1: 72a88f6a48354e91717ca4316a4950b9ffbf44d1 SHA-256: 8adc7286cf4b7f972232764f595f582e0100beaac4922d6b0a09efe66a7768f9
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a signature indicating phishing and trojan behavior. It contains an embedded URI pointing to a Google feed proxy, which is often used to obscure malicious redirects or host phishing content. Although the document body is heavily obfuscated and unreadable, the presence of the URI and the ClamAV detection strongly suggest a phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.1730

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/skout/mBVl/~3/ngfLrbzwjls/uplcv?utm_term=the+invisible+man+questions PDF link annotation