Malicious PDF — malware analysis report

Static analysis result for SHA-256 b36da25e0744aec6…

MALICIOUS

PDF

60.9 KB Created: 2021-09-01 12:19:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-07
MD5: 0db50d1b4aa80f9941720328ec07dc0a SHA-1: 924de9b2c2a43efdc0c8956b1f821d7f1b40f605 SHA-256: b36da25e0744aec67bd1b2a480b4c1c982c25a3c0e41b8865af45c4797b12c75
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a signature indicating phishing and trojan characteristics. It contains embedded URLs, two of which are unknown and potentially malicious, suggesting an attempt to redirect the user to harmful sites. The PDF structure and embedded content do not provide further specific details on the attack's intent beyond URL redirection.

Machine Learning

  • Nyx PDF Classifier clean score 0.0976

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://melz-feu.ru/upload/97894693223.pdf In PDF document text
    • http://beateromer.com/bilder/file/wititawolaIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/3vuEKuznOb8/uplcv?utm_term=what+does+it+mean+ear+ringingPDF link annotation