Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dfc14caa17fa8c2…

MALICIOUS

PDF

391.0 KB Created: 2021-03-31 04:19:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f20254324625ef6120f2a7c4954cb003 SHA-1: 0f900b4baa2b53d434b75f21f152f1c7491f61ba SHA-256: 9dfc14caa17fa8c2629cd4fdb86cb09cc79b6ed1b84235ab4a82161c0f789962
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document identified as malicious by ClamAV. It contains an embedded URL that directs users to a website disguised as a search result for a technical manual, likely a phishing lure. No scripts were extracted from this sample, but the presence of an external URI and the ClamAV detection strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.0335

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/award?keyword=caterpillar+c32+generator+manual+pdf