Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf21aaf5b172a85c…

MALICIOUS

PDF

46.2 KB Created: 2021-04-07 00:54:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7ca7e4f41a86728a88fd48da2d6f6b89 SHA-1: 24187b5170cf8f632465e9d8b33eba61390e11ae SHA-256: bf21aaf5b172a85c59057a8ead603626d0d3cf9bf874b6913198b632d93fd3ba
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document is identified as a phishing lure due to its image-only nature and a clickable action. The embedded URL, https://dugedepap.ru/award?keyword=list+of+surveying+instruments+in+civil+engineering+pdf, likely directs the user to a malicious site. ClamAV and ML classifiers also flagged this file as malicious, reinforcing the phishing and potential malware delivery intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7498

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 46 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/award?keyword=list+of+surveying+instruments+in+civil+engineering+pdf
    • http://nibatuw.iblogger.org/can_i_download_disney_plus_on_apple_tv_3rd_generation.pdf
    • https://cdn.sqhk.co/figakeves/gcAjdFG/zarchiver_apk_download_for_iphone.pdf
    • http://salet.store/36427782444m3q5i.pdf
    • https://cdn.sqhk.co/pobefozo/ijQghhf/sepenibogutowagoma.pdf
    • http://rodina38.ru/47628449703xt4wu.pdf
    • https://cdn.sqhk.co/viwitukaz/SvjcSge/32107469250.pdf
    • http://center-about.com/maximum_ride_books_by_james_pattersonfbfgs.pdf
    • http://faceskinagainbeauty.xyz/sukitebuvibavugfuqnk.pdf
    • https://cdn.sqhk.co/fasisela/4St3ibg/kevuluwenajulomutezob.pdf
    • http://wwnews.site/musical_theatre_performer_salary_uku6f1e.pdf
    • http://loxebosobudi.66ghz.com/94011529250.pdf
    • http://noxofovamoz.epizy.com/31055539424.pdf
    • https://uploads.strikinglycdn.com/files/f98fffdd-d4a1-46e9-8ac8-a2140a270dc1/27975470821.pdf
    • https://9d76d0c6-5807-43ac-a2ba-7b4112d1a20a.filesusr.com/ugd/5cd33b_bddcdde7f7fd4bc29e4aaefd3bf14635.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c8601e84-2f50-41b9-9243-bbff0bd5580f/88871972503.pdf
    • https://uploads.strikinglycdn.com/files/21568dfb-856a-46ac-8728-f8096cbe581d/murder_on_the_orient_express_movie_analysis.pdf
    • https://uploads.strikinglycdn.com/files/3f408f68-e839-4389-a6d0-6eca05cbd9b3/what_is_the_tone_of_because_i_couldnt_stop_for_death.pdf
    • https://58f604bd-1fd8-4cfe-af9b-f15e67d030d5.filesusr.com/ugd/9a7439_70da29197faa47cab5ab1f4143611f8d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a886d3e2-6224-44ad-a3fa-0d61917f5502/crosley_vinyl_player_review.pdf