Malicious PDF — malware analysis report

Static analysis result for SHA-256 dac62e948042f964…

MALICIOUS

PDF

70.9 KB Created: 2021-03-28 13:46:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: d768bce8ef405d666d5a362338e60bb8 SHA-1: b86b8911368887a3d7dbc8cd27493788b2238b7f SHA-256: dac62e948042f964e8b1f1042b8401df75bf8168f49c8def37d1cb71b4f728dd
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8002

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/award?keyword=bus+backside+accident+alert+system+pdf PDF link annotation
    • http://wijasagasipode.getenjoyment.net/3339387854.pdfIn PDF document text
    • http://lnstagramcopyrigtservice.com/jebapocmzsy.pdfIn PDF document text
    • http://jisetatiloro.scienceontheweb.net/tcp_ip_stack_vs_osi.pdfIn PDF document text
    • http://lnstagram-badge-verification.com/wanoraravemupetojda6i.pdfIn PDF document text
    • http://warowusavi.mywebcommunity.org/61950577130.pdfIn PDF document text
    • http://tumuduwaju.mypressonline.com/55866258677.pdfIn PDF document text
    • http://morj.space/desexepugokikosotopiloedoyo.pdfIn PDF document text
    • http://shop-you.xyz/datonujiubzoi.pdfIn PDF document text
    • http://peuly.xyz/how_much_does_a_saxophone_service_costkr1yj.pdfIn PDF document text
    • http://xebobimifu.22web.org/nozibipefojokatodomazu.pdfIn PDF document text
    • http://wadipogi.medianewsonline.com/acls_bradycardia_algorithm_2020.pdfIn PDF document text
    • https://s3.amazonaws.com/lekelepowo/las_medias_de_los_flamencos_resumen_breve.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d04f1be2-ccab-49d6-93d6-aef2f782229b/17574684898.pdfIn PDF document text
    • https://s3.amazonaws.com/pogolo/alex_rider_stormbreaker_trailer_ita.pdfIn PDF document text
    • http://bemuvubovewe.epizy.com/26596603712.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3131d3fe-c8b3-43f1-a568-6340df36b8e4/getting_to_know_arcgis_pro_2.7.pdfIn PDF document text
    • https://s3.amazonaws.com/fifomi/11177348211.pdfIn PDF document text
    • https://s3.amazonaws.com/jaloto/36022702699.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/82eb709d-ed76-4d24-a147-1e5a4ab4aa4b/what_is_the_cheapest_dirt_bike_you_can_buy.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2de3a9a4-5652-4873-950b-c456c0a30cfe/tc_electronic_hall_of_fame_2_vs_mini.pdfIn PDF document text
    • https://s3.amazonaws.com/pasawe/tirasaxedazamunazedu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d1a55902-a81d-49ef-bc64-baf1f9923275/why_is_bolt_action_better_than_semi_auto.pdfIn PDF document text
    • http://tamupevex.rf.gd/36496084915.pdfIn PDF document text
    • https://s3.amazonaws.com/mekonulegipero/40614304344.pdfIn PDF document text
    • https://s3.amazonaws.com/napoledunadigo/desktop_calendar_2020_template.pdfIn PDF document text