Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae88af3633ff8505…

MALICIOUS

PDF

98.6 KB Created: 2021-09-06 10:24:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-12
MD5: 0b089280ac4faac804fb2919d4abc9bc SHA-1: c6bbc70d7b709542bc0b9e6f6515ddd03557d1f8 SHA-256: ae88af3633ff8505c27270a9e80b31c6e3295d18582ee808834f7c8615d1bce9
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains embedded URLs. ClamAV detected this file as a phishing trojan, and ML classifiers also flagged it as malicious. The embedded URLs likely lead to further malicious content or phishing pages, indicating an attempt to trick the user into downloading or interacting with harmful material.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5753

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wildpflanzen-planung.de/file/26707171430.pdf In PDF document text
    • https://alfa-clining.ru/wp-content/plugins/super-forms/uploads/php/files/1bfe1afdb5c2723fa16826e05b81ca5d/lixokomux.pdfIn PDF document text
    • http://uelzecht.lu/userfiles/files/47250612471.pdfIn PDF document text
    • https://www.zochrot.org/ckfinder/userfiles/files/48954693307.pdfIn PDF document text
    • http://izeninfo.net/admin/upload/files/11949147312.pdfIn PDF document text
    • http://carnavaldemarbella.com/Senegal_5/Content/files/userfiles/file/lugijonakosox.pdfIn PDF document text
    • https://airflow-skateboards.com/upload/file/filitefep.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/S30rS-6n6vg/uplcv?utm_term=nacionalismo+cultural+definicion+pdfPDF link annotation