Malicious PDF — malware analysis report

Static analysis result for SHA-256 c5e4e014a23139d9…

MALICIOUS

PDF

41.6 KB Created: 2021-09-17 22:55:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-25
MD5: a6334cf01f1293dd91d61f9d83c2e8ee SHA-1: d1b5a9c5239f446bf053d8de1c0949df69a2c66d SHA-256: c5e4e014a23139d99ef10fa6c71d1c4dccb0e6919dffd2314cdc44b89a98f79f
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as a phishing trojan by ClamAV. It contains multiple embedded URLs, several of which are flagged as unknown reputation, suggesting they may lead to malicious content. The PDF structure and embedded URLs indicate an attempt to direct the user to external sites, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3277

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://iucecb.com/files/file/nifaromimawileseravi.pdf In PDF document text
    • https://www.tri-or.fr/tri-or/ckfinder/userfilesfiles/posemetuwotibe.pdfIn PDF document text
    • http://vegasoft.hr/wp-content/plugins/formcraft/file-upload/server/content/files/1613de9500a7c2---53412356977.pdfIn PDF document text
    • https://gastriklandsbf.se/UserFiles/files/ronise.pdfIn PDF document text
    • https://dongcohonda.com/userfiles/file/82256977500.pdfIn PDF document text
    • http://hoachattn.com/image/files/12053324941.pdfIn PDF document text
    • http://clearlakesd.org/wp-content/plugins/formcraft/file-upload/server/content/files/1613ff5e98b206---zewafuzebisumifoz.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/3vuEKuznOb8/uplcv?utm_term=best+offline+navigation+app+for+android+2021PDF link annotation