Malicious PDF — malware analysis report

Static analysis result for SHA-256 cf0b031ceb830371…

MALICIOUS

PDF

70.6 KB Created: 2021-01-24 11:17:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 44ebc1b1be482e47819a8ebeb2352d25 SHA-1: ff5515b43892339c76da5015ab8cefd9d63bac1c SHA-256: cf0b031ceb8303712e2898737c297d1b1d512137a391f5a9711012de374af067
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9569

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wb?keyword=party%20in%20the%20usa%20release%20date PDF link annotation
    • http://tegonur.22web.org/zoledakasuzofexanovumul.pdfIn PDF document text
    • http://ketokod.iblogger.org/live_sports_hd_tv_app_for_android.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4473053/normal_5ffb44d77068e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4383470/normal_5fde290000972.pdfIn PDF document text
    • http://verification-help.com/asteroid_impact_earth_2036n239k.pdfIn PDF document text
    • http://natlegend.space/the_culture_projectdt3lw.pdfIn PDF document text
    • https://cdn.sqhk.co/sabimejuka/cgcKNBH/wufukitupazararudetatoxe.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4446650/normal_5fe26b3d31ea2.pdfIn PDF document text
    • https://cdn.sqhk.co/gefimiwotux/ghggdtR/penutakivenofalure.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4464720/normal_5ff07ab322881.pdfIn PDF document text
    • http://mini-camera-super.club/shoot_em_up_games_iosodqd5.pdfIn PDF document text
    • https://cdn.sqhk.co/dodamewope/xMhfhf9/sazebemodebup.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4380070/normal_5fc8aae8c5df0.pdfIn PDF document text
    • http://mediaverifiedbadge.com/centurylink_voip_portal_loginfb6tu.pdfIn PDF document text
    • http://putinoid.ru/circuit_electrique_va_et_vient_2_interrupteursepz5t.pdfIn PDF document text
    • http://valamujunitun.epizy.com/pdf_converter_compress.pdfIn PDF document text
    • http://poziluxolebulu.epizy.com/you_ll_be_back_violin_sheet_music.pdfIn PDF document text
    • https://s3.amazonaws.com/gonafoziguwewe/dictionary_french_to_english_free.pdfIn PDF document text
    • https://s3.amazonaws.com/jeromisixinolib/english_practice_test_with_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/wurivuve/codices_mixtecos.pdfIn PDF document text
    • https://s3.amazonaws.com/genedonapubefe/bass_guitar_tuner_free_for_mobile.pdfIn PDF document text