Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0629914f5fac7dd…

MALICIOUS

PDF

302.9 KB Created: 2021-03-13 21:08:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: d67fa68a06876eab33c0d9a81a1c76f5 SHA-1: 1cd4688a8545ade61539942dc7ec23d29ac26b48 SHA-256: c0629914f5fac7dd5e0f9d66d60aa9c40e8d18a8c97ffdcfa9726323835fa1c3
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, 'seumenha.ru', which is likely used to deliver a malicious payload or conduct phishing. The document body, though truncated, suggests a lure related to a 'fitness plan'. No scripts were extracted, but the presence of an external URI and the malware classification strongly indicate a malicious intent to redirect the user to a harmful site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6019

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/award?keyword=fitness+plan+for+beginners+pdf PDF link annotation
    • http://sodahq.pro/968236893428v4ob.pdfIn PDF document text
    • http://eagleaff.com/28847673898no2xw.pdfIn PDF document text
    • http://opticsystem.website/one_day_in_the_life_of_ivan_denisovich_themesng9ik.pdfIn PDF document text
    • http://erse.xyz/made_in_chelsea_croatia_episode_guidedcn5l.pdfIn PDF document text
    • http://vitodibiwanezej.mypressonline.com/12473366702.pdfIn PDF document text
    • http://lady-bug.club/xokejebezivagasole8rapb.pdfIn PDF document text
    • http://medicinfo.online/jafewipasuwamiw0tt8.pdfIn PDF document text
    • http://dressnbuy.com/free_printable_math_worksheets_times_tablesckww3.pdfIn PDF document text
    • http://xepidenad.scienceontheweb.net/agnus_dei_sheet_music.pdfIn PDF document text
    • http://wisidakofaxom.iblogger.org/bose_awrcc1_remote.pdfIn PDF document text
    • http://puliliraforuwu.22web.org/63353450974.pdfIn PDF document text
    • http://worelimupuvefam.mywebcommunity.org/burger_king_specials_breakfast_menu.pdfIn PDF document text
    • http://uplrezina.site/what_is_the_best_karcher_jet_washr5kr8.pdfIn PDF document text
    • http://handler-autoscout24.com/bleacher_report_live_chelsea_vs_valenciazb86k.pdfIn PDF document text
    • https://7e8267f5-6380-480e-ad72-df526eaefc07.filesusr.com/ugd/cbe325_fa69cb9549694deeab615b5433f90b64.pdf?index=trueIn PDF document text
    • http://sivigowukom.epizy.com/vibinakivuvepudiduvete.pdfIn PDF document text
    • https://ec8c99fd-5413-4e38-b6a0-2ccbba71fc6f.filesusr.com/ugd/de02f3_1902eb18eada4f2097140204760c177f.pdf?index=trueIn PDF document text
    • https://c84d532c-3b33-47d6-96aa-4134a1164eb1.filesusr.com/ugd/6d45f6_73f9081032e94f11a13e51120990ea2f.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/ab199608-eb9b-4f4c-9ed3-5f5d23201ae3/perfect-english-grammar.com_past_participle.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/595ca430-8e4e-4dde-a5ec-614a6d08e7b2/sierra_60_gr_tmk_223_load_data.pdfIn PDF document text
    • https://8d67285a-e3c5-4820-bb1a-bb91ce1079a6.filesusr.com/ugd/d54300_f569f023e2e34633b31d6b2fa27a74b2.pdf?index=trueIn PDF document text
    • http://kagumabexa.rf.gd/34194236694.pdfIn PDF document text
    • https://cda84be5-0c54-4c05-8389-97bb004c798d.filesusr.com/ugd/fa9f00_299973c1379244718deb0e3829b30e86.pdf?index=trueIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00015285.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x15285 296624 bytes
SHA-256: 0a270e21b83f4aeb1fe75a4a27e6dbe622031cff12e8da0171609d2699c454e0