Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5408df011774ba0…

MALICIOUS

PDF

83.8 KB Created: 2021-07-18 15:07:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-05
MD5: 9024d8d073494dce4163efae884c9367 SHA-1: d6ddbcbba1935f731e385392ef49c41664082808 SHA-256: d5408df011774ba06e7a2ccc27489ccc5d751415a8a9e5f0cad5b9927c8fe8ff
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains embedded URLs pointing to potentially malicious sites. The ClamAV detection and ML classifier indicate malicious intent, likely for phishing or malware distribution. No scripts were extracted, but the presence of external URIs suggests an attempt to redirect the user to a compromised or malicious resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5344

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://objetivovender.com/wp-content/plugins/formcraft/file-upload/server/content/files/160756df845987---famebeg.pdf In PDF document text
    • http://thongthien.vn/upload/files/89485521623.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=bs+grewal+exercise+solutionsPDF link annotation