Malicious PDF — malware analysis report

Static analysis result for SHA-256 8fe53c2e1d04f082…

MALICIOUS

PDF

54.5 KB Created: 2021-10-05 21:57:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-25
MD5: 4d6c548f63bdfca8bff2bd334ffbce21 SHA-1: 291f623474bbe49c8a6ec55080b3641766ac19cc SHA-256: 8fe53c2e1d04f08205a30565b34038e2e2bb053a9e7b5c910d9ae424de59dbbb
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV and an ML classifier, indicating it's a phishing attempt. The embedded PDF contains multiple unknown URLs, suggesting a lure to download further malicious content. No scripts were extracted, limiting the analysis of specific execution behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5056

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://etimes.mn/uploads/files/najebelepil.pdf In PDF document text
    • http://habitat3.eu/userfiles/files/basebozowisiv.pdfIn PDF document text
    • http://kolesnikov.pro/ckfinder/userfiles/files/zajipezuripefodiniralifa.pdfIn PDF document text
    • http://dealershop.es/camarasegovia/userfiles/file/18724452281.pdfIn PDF document text
    • https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/b58a18594035c5d75e9a5803a7512594/juwaponuzofisux.pdfIn PDF document text
    • http://autoscuolapezzano.it/userfiles/files/29175740633.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/GLLx1DTH0VQ/uplcv?utm_term=saul+alinsky%27s+rules+for+radicals+pdfPDF link annotation