Malicious PDF — malware analysis report

Static analysis result for SHA-256 d03194080a0f675d…

MALICIOUS

PDF

51.7 KB Created: 2021-03-12 22:14:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: da80bd308033c1b585cba442988c92b5 SHA-1: 04cf9d3984c51f1e05cf413b3ea76ae440f67ba1 SHA-256: d03194080a0f675df0af1c7cc57b6a2dd8b821ffed37706df3532dfa7c1dff5e
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as an image-only lure, typical of phishing campaigns, containing a clickable link to an external URL. ClamAV and ML classifiers also flagged this file as malicious. The primary IOC is the external URL which likely leads to a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7339

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 51 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/award?keyword=franchising+pdf+slideshare
    • https://cdn-cms.f-static.net/uploads/4391335/normal_604395347b234.pdf
    • http://vienvozvrat.site/sezokarofugewenugezewemifwf6e.pdf
    • https://static.s123-cdn-static.com/uploads/4380090/normal_5fdde8d6b0f47.pdf
    • http://tuzupibu.scienceontheweb.net/winebilasupamosa.pdf
    • http://evromotors.net/egyptian_mythology_book_seriesj8bgh.pdf
    • http://citruss.space/mapikirefezupapogebujavmzto5.pdf
    • http://gugezebaz.mygamesonline.org/ganapati_atharvashirsha_lyrics_marathi.pdf
    • http://pusolaxunu.66ghz.com/pioneer_deh-1300mp_installation_guide.pdf
    • http://berasowugixo.mywebcommunity.org/22262170418.pdf
    • http://wajofima.mywebcommunity.org/bixididagifativez.pdf
    • http://trastenmyqort.online/femegajikanfq2sm.pdf
    • https://uploads.strikinglycdn.com/files/6859e010-bb39-4962-8587-3b4fd6b20db7/simple_present_question_exercises.pdf
    • https://uploads.strikinglycdn.com/files/5adf1b57-ab24-49ab-8dd3-2ed567dee740/7903216689.pdf
    • https://uploads.strikinglycdn.com/files/1abf4a76-057d-4f50-bd36-e6eaa386438d/24922909491.pdf
    • https://uploads.strikinglycdn.com/files/94d6e0f8-31b6-4a0b-b30d-72a87f68cfa6/27426253002.pdf
    • http://bodegifu.atwebpages.com/mcdonalds_marketing_mix_physical_evidence.pdf
    • http://bexudogi.rf.gd/zagikiguvinejebaje.pdf
    • https://uploads.strikinglycdn.com/files/f88b9908-fa88-4bc9-bea3-83fb15387734/how_to_install_android_9_on_nexus_7.pdf
    • https://uploads.strikinglycdn.com/files/c60cacb4-6796-4500-9a61-be885d6f5073/vanobes.pdf
    • https://uploads.strikinglycdn.com/files/09863be5-acba-4ec5-830b-cddc73d93f1f/love_story_novel_by_erich_segal_read_online_free.pdf