Malicious PDF — malware analysis report

Static analysis result for SHA-256 947250e032895b50…

MALICIOUS

PDF

51.7 KB Created: 2021-03-22 12:02:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 946317f633fa48d43c5169a5685f6e49 SHA-1: c87bc6d0fcebb465368f3e07dfc9aac9d11ee5f4 SHA-256: 947250e032895b5030865c5f654cfeadea27faba6ebe48ca17d4af0979aeb317
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5557

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/award?keyword=centrifugal+pump+head+calculation+formula+pdf PDF link annotation
    • https://cdn.sqhk.co/pegebatanuz/7jjCLgd/adventures_of_tintin_android_game_free.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374360/normal_5fda41bb84b4e.pdfIn PDF document text
    • http://zefutuwukeras.getenjoyment.net/xitufemerojanofu.pdfIn PDF document text
    • https://cdn.sqhk.co/vixonafom/ZifjcOL/tippy_toe_tippy_toe_and_stop.pdfIn PDF document text
    • https://cdn.sqhk.co/mekaxuzoxu/dgpghxE/descargar_wrestling_revolution_3d_mod_wwe_2k19_apk.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368221/normal_5fd262b46861f.pdfIn PDF document text
    • http://jonotijero.medianewsonline.com/78968969445.pdfIn PDF document text
    • https://cdn.sqhk.co/pifonode/eibhage/barijikepasilubaturu.pdfIn PDF document text
    • http://vizemezezu.sportsontheweb.net/voxuzadefo.pdfIn PDF document text
    • https://cdn.sqhk.co/bomoxale/1hjjchd/internet_fashionista_dress_up_game_download.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470964/normal_601f603769cfa.pdfIn PDF document text
    • http://pirewarekow.mywebcommunity.org/what_is_the_structure_of_an_informative_essay.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4461773/normal_603cb539a43fa.pdfIn PDF document text
    • https://246406bc-bb0d-4f29-baed-d8a6153a9543.filesusr.com/ugd/3ddeef_8054b8bfbf504491bf997826144ab14d.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/jadudusujuje/android_bootloader_interface_driver_windows_8.pdfIn PDF document text
    • https://s3.amazonaws.com/xepululejiwof/fejatuwigufekumu.pdfIn PDF document text
    • https://45f61934-b4a1-4335-a9e3-e142d9465b5b.filesusr.com/ugd/0dd040_cf4f336c85104288b6305dd62e0f6d5a.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/sezebepit/apologize_song_320kbps.pdfIn PDF document text
    • http://taberadajip.atwebpages.com/administracion_de_la_cadena_de_suministro_chopra_4ta_edicion.pdfIn PDF document text
    • https://f635e5d9-31b1-4f19-b758-7a623be10181.filesusr.com/ugd/6cf0f5_871bc86ae1b54e2bbe24d15945fafefd.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/bupaxomu/64847335653.pdfIn PDF document text
    • https://88966db1-4a83-4446-b941-f65022a6235f.filesusr.com/ugd/928e0f_22ddaa3f5e6b4b52a387a0911e585eb8.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/lonozote/nuwapu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/acac8a48-a945-4881-98ef-ffe9a7990ecc/7126816235.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa3a380a-e797-4b8d-ab28-3668ab51d679/poker_21_movie.pdfIn PDF document text
    • https://de2ee6d5-caaa-4265-b15c-40100ab77d99.filesusr.com/ugd/d43733_80acfb050b624c09b268af07b4f42c32.pdf?index=trueIn PDF document text