Malicious PDF — malware analysis report

Static analysis result for SHA-256 aff19c578be67843…

MALICIOUS

PDF

63.1 KB Created: 2021-04-29 10:51:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 1178219df8bdc773c2c9c21dcf478b49 SHA-1: f01c85d6781ce2e0b6347c8240947fab5678c441 SHA-256: aff19c578be67843689a9e9d670b6f4f35c0b44d84e73486cc7e619c15ca84ab
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains an embedded URL pointing to a malicious domain. The document body, though heavily obfuscated, appears to reference a movie title, suggesting a lure to entice users to click the malicious link. The presence of the PDF_URI heuristic and the ClamAV detection strongly indicate malicious intent, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7351

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/strik?utm_term=how+true+is+the+zookeeper%2527s+wife+movie PDF link annotation
    • http://piwofoterif.sportsontheweb.net/mudupesaxulatope.pdfIn PDF document text
    • http://rululidevasuv.22web.org/new_camptown_races_fiddle_tune_sheet_music.pdfIn PDF document text
    • http://lotibamuzuti.scienceontheweb.net/pidibufevadarolezi.pdfIn PDF document text
    • http://xenojupu.mywebcommunity.org/solek.pdfIn PDF document text
    • http://taxokijoba.sportsontheweb.net/jingle_bell_rock_lyrics.pdfIn PDF document text
    • http://kewokuxumuzig.medianewsonline.com/48794751386.pdfIn PDF document text
    • http://ranupila.mywebcommunity.org/tewonikixedefobileb.pdfIn PDF document text
    • https://s3.amazonaws.com/xetasif/kesinodukimarajuse.pdfIn PDF document text
    • https://s3.amazonaws.com/tarizirefevifab/case_information_travis_county.pdfIn PDF document text
    • http://kejusekijo.epizy.com/angles_worksheet_for_grade_4.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/234200b0-2840-434a-8dcf-cdeaa8cb0699/74210415574.pdfIn PDF document text
    • https://s3.amazonaws.com/xidulumexi/wimumuxipe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/258d72e3-a05e-450d-873e-4e964e715843/sugixevegemetusiriragupe.pdfIn PDF document text
    • https://s3.amazonaws.com/leteraxewe/main_characters_in_world_war_z_book.pdfIn PDF document text
    • https://s3.amazonaws.com/bejenosugede/gagufapa.pdfIn PDF document text
    • https://s3.amazonaws.com/towakog/charla_de_seguridad_covid_19.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dbb4626c-30cd-4868-9750-e7dad38ab2d0/is_samsung_crystal_uhd_any_good.pdfIn PDF document text
    • https://s3.amazonaws.com/ponivotigegepub/53202625610.pdfIn PDF document text
    • http://dixolasafu.epizy.com/sasexetizijusur.pdfIn PDF document text
    • https://s3.amazonaws.com/duzexefemosaxe/pebivivesupil.pdfIn PDF document text