Malicious PDF — malware analysis report

Static analysis result for SHA-256 9cd9929368da1330…

MALICIOUS

PDF

59.6 KB Created: 2021-03-19 19:12:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8e6afc6ec5e828593034d08c853ff13d SHA-1: 48876b4b3133997f37fb3e704370fdb99abc766c SHA-256: 9cd9929368da13304c85ff738ba33b716d7413528e55a392cfa7e81369f57a6e
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains an embedded URI pointing to a suspicious domain, likely intended to deliver a secondary payload or redirect the user to a phishing site. The document body, though heavily obfuscated, suggests a lure related to 'Aswb bachelors study guide free', aligning with a phishing or social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9869

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/strik?utm_term=aswb+bachelors+study+guide+free
    • https://static.s123-cdn-static.com/uploads/4369648/normal_5fcca6ddb06cb.pdf
    • http://nanebaxexob.getenjoyment.net/how_much_does_it_cost_to_replace_a_rooftop_air_conditioner.pdf
    • https://static.s123-cdn-static.com/uploads/4500665/normal_5ff318d23ecf0.pdf
    • https://cdn-cms.f-static.net/uploads/4470524/normal_60431ab957228.pdf
    • http://riniwodifole.medianewsonline.com/can_sketchbook_open_psd_files.pdf
    • http://vetozadep.mywebcommunity.org/how_much_does_an_anesthesiologist_make_in_residency.pdf
    • https://cdn-cms.f-static.net/uploads/4446168/normal_60131e1b109b9.pdf
    • https://static.s123-cdn-static.com/uploads/4487663/normal_5ffe464491188.pdf
    • https://cdn-cms.f-static.net/uploads/4486354/normal_604315a8364fe.pdf
    • http://kyrgyztours.com/jekoxuwinufajewexagokezutn6zov.pdf
    • http://lilubaxubaxulu.sportsontheweb.net/how_to_clean_krups_coffee_maker.pdf
    • http://lipuwisapi.mywebcommunity.org/15528842829.pdf
    • https://cdn-cms.f-static.net/uploads/4491164/normal_6021c8d1e9db1.pdf
    • http://smartcreditcheck.info/95575946893rrbka.pdf
    • https://s3.amazonaws.com/jozetej/bumujaropanufirane.pdf
    • https://uploads.strikinglycdn.com/files/5c72e4c7-6d85-4f01-aaab-c37c62d5ff82/samsung_m2880fw_toner_cartridge.pdf
    • https://s3.amazonaws.com/pavujiniz/51581125795.pdf
    • https://s3.amazonaws.com/xonaxevetaf/59647309180.pdf
    • https://s3.amazonaws.com/boduxatavepe/paradise_fire_news_reports.pdf
    • https://s3.amazonaws.com/jebupofedijakuk/23758414056.pdf
    • https://uploads.strikinglycdn.com/files/817abcf6-9a2b-4a88-b717-99ee70a58c7c/what_is_the_appropriate_definition_of_information_technology.pdf