Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4354e66b32af0ae…

MALICIOUS

PDF

54.1 KB Created: 2020-12-06 02:21:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1fd17ba31b96e8783a21f9b208182f02 SHA-1: 118ff80a459ba5dc52997712db324eebcf2933b0 SHA-256: c4354e66b32af0ae03235570c4cfae94851e1fa37e8115ae7098df552e994cc6
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains an embedded URI that redirects to a URL associated with Minecraft, likely a lure to entice users to click. ClamAV detection and ML classification indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6226

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/wb?keyword=minecraft%20windows%2010%20edition%20%201.%2014
    • https://cdn-cms.f-static.net/uploads/4368760/normal_5fb7a6440c73e.pdf
    • https://cdn-cms.f-static.net/uploads/4454995/normal_5fad477dce35e.pdf
    • https://static1.squarespace.com/static/5fc5b8d58ef7301f8b31fd81/t/5fc5e0213485235c869205a8/1606803489986/52656172300.pdf
    • https://static1.squarespace.com/static/5fc17674e9fc3622d5261a8e/t/5fcb202f26a2be7f6ddf4c49/1607147568544/durigasag.pdf
    • https://static1.squarespace.com/static/5fc6665e11f6a41984ab41ad/t/5fc779043d56556d143f1479/1606908166721/diy_cnc_router_tool_changer.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4e213485235c86bcd0f1/1606372897473/66798705242.pdf
    • https://s3.amazonaws.com/zazelujeju/capitulo_6b-_2_affirmative_tu_commands_answers.pdf
    • https://s3.amazonaws.com/gonuxiwela/youth_renew_face_cream_reviews.pdf
    • https://s3.amazonaws.com/nevovumowa/abc_worksheets_for_kindergarten.pdf
    • https://static1.squarespace.com/static/5fc0eac55bcb0228a2828fa5/t/5fc100555147b14804575073/1606484054068/canary_diamond_ring_fake.pdf
    • https://s3.amazonaws.com/divikufifir/kenmore_elite_stove_manual.pdf
    • https://s3.amazonaws.com/ravuxudibure/complete_the_hundreds_chart_worksheet.pdf
    • https://static1.squarespace.com/static/5fc1945f2bbd7406580b5c60/t/5fc860bf7ff5a343ebf39b70/1606967487465/kixajiwigemapokiraweros.pdf