Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfde7cb9a62b7d75…

MALICIOUS

PDF

62.2 KB Created: 2021-03-09 19:00:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4f478961071407f77beee729f5692127 SHA-1: 8ead049216dfb4839398f07abc866128cacf96ce SHA-256: bfde7cb9a62b7d758737405c02c121b5531e053201480a4fbf4072d556943644
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document identified as malicious by ClamAV. It contains an embedded URI pointing to 'seumenha.ru', which is likely a phishing or malware distribution site. The document body, though heavily obfuscated, appears to be a lure related to a song title, suggesting a social engineering tactic to entice users to click the malicious link. No scripts were extracted, but the presence of an external URI and the ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4988

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wb?keyword=a%20song%20for%20lya%20george%20rr%20martin
    • https://cdn-cms.f-static.net/uploads/4373271/normal_5fdc0d11979af.pdf
    • https://cdn-cms.f-static.net/uploads/4468286/normal_60199d3049d1f.pdf
    • https://cdn-cms.f-static.net/uploads/4381976/normal_5fe6c898b16a6.pdf
    • https://cdn-cms.f-static.net/uploads/4418567/normal_600a5190089b3.pdf
    • http://trylait.club/arbys_menu_nutrition_side_salad51tzx.pdf
    • http://sesaxojatox.iblogger.org/maytag_2000_series_washer_error_code_lf.pdf
    • http://yoga-italy.space/operations_research_taha_9th_editioneme1f.pdf
    • https://cdn-cms.f-static.net/uploads/4483083/normal_602a308c9300d.pdf
    • https://cdn-cms.f-static.net/uploads/4418788/normal_6017cced50f39.pdf
    • http://nakanilo.club/55631932603rnri4.pdf
    • https://cdn-cms.f-static.net/uploads/4470223/normal_60383fb053332.pdf
    • https://cdn-cms.f-static.net/uploads/4422180/normal_600fd6634cbde.pdf
    • https://cdn-cms.f-static.net/uploads/4498997/normal_600a763ad9966.pdf
    • http://navibizo.rf.gd/56512977334.pdf
    • https://s3.amazonaws.com/xifabilejilab/aatish_movie_song_free.pdf
    • https://s3.amazonaws.com/tinivukedeta/alternanthera_sessilis.pdf
    • https://s3.amazonaws.com/jenagubadopi/63387044382.pdf
    • http://melaworogafema.epizy.com/easy_formal_updos_for_thin_hair.pdf
    • https://s3.amazonaws.com/zomuzigo/woperovowesewusi.pdf
    • https://s3.amazonaws.com/xijalovelokolep/mosilemifesonorejoxenos.pdf
    • http://munugarufidapob.rf.gd/40453893981.pdf
    • https://s3.amazonaws.com/nawosineromigi/great_wall_of_china_project_management.pdf
    • http://bobiwaj.rf.gd/optimate_4_car_battery.pdf