Malicious PDF — malware analysis report

Static analysis result for SHA-256 daf5bbed811a7031…

MALICIOUS

PDF

63.0 KB Created: 2021-03-04 17:41:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 62bc711615386775ca09c288d4508a71 SHA-1: b74a088dc0531be41829021c9821b9819a6e1e75 SHA-256: daf5bbed811a703122f0bb6df8f28eced7d8e55a8a83167f208cf1193ea73003
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a heuristic firing for an external URI pointing to a suspicious domain, which is also listed as an IOC. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were extracted, the presence of a suspicious URL within the document body suggests a phishing or redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7116

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/strik?utm_term=digital+prism+universal+remote+codes
    • http://damodudajipofem.22web.org/calculus_2_jkuat.pdf
    • http://sagokorize.22web.org/samsung_un32eh5300_bluetooth_headphones.pdf
    • https://s3.amazonaws.com/minaxigevani/subject_verb_agreement_worksheet_grade_8.pdf
    • http://zekarevuwo.epizy.com/stanley_fatmax_powerit_1000a.pdf
    • https://s3.amazonaws.com/pisik/cateye_velo_wireless_cc-_vt235w_manual.pdf
    • https://s3.amazonaws.com/zunaporam/botim_free_uptodown.pdf
    • http://luwawabegopit.rf.gd/30652657760.pdf
    • https://s3.amazonaws.com/lorugipopuxe/2048255637.pdf
    • https://s3.amazonaws.com/zidosozawok/nibupavuputifopafojewivor.pdf
    • https://s3.amazonaws.com/kewuxejikiwe/rutiwekizogufosuge.pdf
    • https://s3.amazonaws.com/bakoloj/auditor_report_mean.pdf
    • http://mukanebesiva.atwebpages.com/ways_to_celebrate_anniversary_during_covid.pdf
    • https://s3.amazonaws.com/xebuvuwov/namulugajojuxojopol.pdf
    • http://mogozuru.rf.gd/heroes_3_factions_guide.pdf
    • https://s3.amazonaws.com/xidazeze/gopujabop.pdf
    • http://duxegejuw.atwebpages.com/fence_system_for_old_craftsman_table_saw.pdf
    • https://s3.amazonaws.com/wukara/conceptual_physics_fundamentals_practice_book_answers.pdf
    • https://s3.amazonaws.com/purawuma/zofesevogovajarifubusaxus.pdf
    • https://s3.amazonaws.com/gidibesuxi/geluxazemorakezulirija.pdf