Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4ffbc52e746ee35…

MALICIOUS

PDF

49.6 KB Created: 2021-02-19 02:57:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-05
MD5: d8f595605d20fcd6ee30e9f12ebf1a6f SHA-1: dda3aa9f01a1d7899e4d53fe1ee066a0bd210789 SHA-256: c4ffbc52e746ee35dc8f5fbabbd07ae64d2c0bb9632302c15d7282e8086c72fd
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing an embedded URL that points to a suspicious domain. Heuristics indicate this is a phishing attempt, likely leveraging the document's content to trick the user into visiting the malicious link. No scripts were extracted from this sample, but the PDF structure itself facilitated the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6101

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/aws?utm_term=pathfinder+kingmaker+weapon+finesse+unarmed PDF link annotation