Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c8d519cf42fab20…

MALICIOUS

PDF

51.2 KB Created: 2021-07-24 03:43:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-12
MD5: 92e665de54d02105e8d9dece2cb27b66 SHA-1: 18b74995c99c5b3cfb4e33bf6a96589b985a1fcc SHA-256: 9c8d519cf42fab209dfa3ccbee4991d27ee3bde2d473cd54f4cdb78e340c70ec
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a phishing detection. It contains an embedded URI that points to a URL, which is likely intended to lead the user to a phishing site. While no scripts were extracted, the presence of an embedded URI in a PDF is a common technique for phishing attacks.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4220

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/Om9ozkHLxGw/uplcv?utm_term=los+patitos+feos+resumen PDF link annotation