Malicious PDF — malware analysis report

Static analysis result for SHA-256 de2ffbd5b2881dfd…

MALICIOUS

PDF

73.6 KB Created: 2021-04-04 03:36:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 527749c665c20e29d0353769f63a37a5 SHA-1: e38613b8cc40f63d50abe8dcfc5ade172afeef2b SHA-256: de2ffbd5b2881dfde69d3fcac705ebd8b982166c81ce895c6f94b41155a6ea53
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is a PDF that contains an embedded URI pointing to a suspicious URL, which is likely a lure for a phishing or malware download attempt. ClamAV and ML classifiers also flagged this PDF as malicious, indicating it likely exploits a vulnerability or contains malicious content. The presence of a suspicious URL and the nature of the ClamAV detection suggest an attempt to trick the user into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7989

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=java+spring+framework+tutorial+pdf
    • http://gojavodevagajuw.mygamesonline.org/how_to_connect_hp_printer_to_wireless_network_on_mac.pdf
    • http://jawazapefaxuzit.mywebcommunity.org/40001866701.pdf
    • https://vutuwoti.weebly.com/uploads/1/3/4/7/134720014/567f445.pdf
    • http://sitebomobegux.sportsontheweb.net/mutusizibotojuvufowubuko.pdf
    • http://kigowamukidiba.iblogger.org/riwidisade.pdf
    • https://gedikorewugeg.weebly.com/uploads/1/3/0/7/130775309/dd474b70.pdf
    • http://zugemenelil.medianewsonline.com/karmakshetra_bengali_newspaper_today.pdf
    • http://wasalesex.epizy.com/application_format_for_applying_teacher_post.pdf
    • http://bogiginilaxano.epizy.com/neuroanatomy_through_clinical_cases_by_hal_blumenfeld.pdf
    • http://teporududa.rf.gd/ameline_eric_sammut.pdf
    • http://nitusul.rf.gd/clash_of_clans_pc_windows_xp.pdf
    • https://uploads.strikinglycdn.com/files/46a589f3-8d28-482c-af8b-fd324eb91dc7/10_naeyc_standards.pdf
    • https://uploads.strikinglycdn.com/files/e3e2a404-d860-47fa-bf45-e2e5cf882263/hampton_bay_e75795.pdf
    • https://s3.amazonaws.com/sevoga/5359195270.pdf
    • http://bovifuxabobi.epizy.com/jsw_energy_annual_report.pdf
    • https://s3.amazonaws.com/nowonovege/pewetafusogavidezi.pdf
    • https://s3.amazonaws.com/moduxanakuri/pagonimoja.pdf
    • https://s3.amazonaws.com/padosumifubobo/canada_visa_family_information_form_signature.pdf
    • https://uploads.strikinglycdn.com/files/a8390e35-3337-4bdf-937b-d56e23066053/32888387089.pdf