Malicious PDF — malware analysis report

Static analysis result for SHA-256 de8cc0ae293e60f3…

MALICIOUS

PDF

66.6 KB Created: 2021-06-01 10:29:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d6c88ceb16bdc49d18e881fd1a41fe8f SHA-1: 72224ae7948fb583e3836c7d40491f111245552a SHA-256: de8cc0ae293e60f39a7e875f3084f2b88f50b795822d53484eedda71827b1d7d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF that contains an embedded URL disguised as a free download for 'Vedic maths pdf free download in marathi'. Heuristics and ML classifiers indicate malicious content, and ClamAV specifically flags it as a phishing trojan. The primary IOC is the external URL used in the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8274

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ketchas.ru/pbw?utm_term=vedic+maths+pdf+free+download+in+marathi
    • https://uploads.strikinglycdn.com/files/8926415c-3cf7-45b8-b5b7-cef30546dbbe/bissell_spotbot_pet_33n8_manual.pdf
    • https://uploads.strikinglycdn.com/files/c046d8d5-5050-4279-bf4b-bc776364a106/ejercicios_resueltos_de_balances_activo_pasivo_y_patrimonio_neto.pdf
    • https://uploads.strikinglycdn.com/files/ef50c2a3-cc1a-455e-8955-682ef57f7f26/navy_eval_input_form.pdf
    • https://uploads.strikinglycdn.com/files/2e3d4b85-d74f-4418-9195-e25c8fdc2d7d/northeastern_university_academic_calendar_2015-16.pdf
    • https://uploads.strikinglycdn.com/files/bef0be7a-4185-4384-8522-3bef68781e52/84250273856.pdf
    • https://uploads.strikinglycdn.com/files/3005103c-c33f-4089-949c-79f23e11ae02/kivawusenotun.pdf
    • http://sorawako.pbworks.com/f/conjuguemos_preterite_vs_imperfect_5_answers.pdf
    • http://nusuwoxub.pbworks.com/f/windows_loader_2.2_2_by_daz_activator_windows_7_free_download.pdf
    • https://uploads.strikinglycdn.com/files/547f27cc-0c1f-46e1-9162-d31797d2e229/75478012371.pdf
    • http://vibevekofano.pbworks.com/w/file/fetch/144426585/shapes_worksheets_for_preschool.pdf
    • https://uploads.strikinglycdn.com/files/553f44be-7dd5-4368-8807-9e25c4573062/52689852849.pdf
    • http://tagexoba.pbworks.com/w/file/fetch/144422664/gozivix.pdf
    • https://uploads.strikinglycdn.com/files/7ea16fb9-dffd-4fd2-b801-c090bfd54115/rufugeposituxisobusezono.pdf
    • https://uploads.strikinglycdn.com/files/e67925ad-dee4-4f28-8237-cb63583ced5e/descripcion_de_los_personajes_del_libro_el_amor_en_los_tiempos_del_colera.pdf
    • https://uploads.strikinglycdn.com/files/7de05912-0f32-4ff7-8111-6408367d44d2/que_es_un_oso_panda_grande.pdf
    • https://uploads.strikinglycdn.com/files/345f6fc6-0e4a-4d63-988f-67d9ccbff597/what_size_bobbin_for_singer_4411.pdf
    • https://uploads.strikinglycdn.com/files/c33e0bf2-85de-4445-bd56-d2d9d169a1de/interrogative_pronouns_worksheet_grade_10.pdf
    • https://uploads.strikinglycdn.com/files/b73816f1-fb0b-4e3b-9e65-68ebf0d6ca96/24713477740.pdf
    • http://wuvebag.pbworks.com/w/file/fetch/144428778/solving_systems_of_equations_by_graphing_worksheet_answer_key_kuta_software.pdf
    • https://uploads.strikinglycdn.com/files/2fc7cced-8138-4eb3-b378-402f2a8efcac/what_is_the_punishment_in_the_7th_circle_of_hell.pdf
    • https://uploads.strikinglycdn.com/files/7383d73e-d36f-4473-ab19-5aaa6d7cf1b1/how_to_relieve_back_pain_when_pregnant.pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5b4.bin
138f9912586df256a75159556a74aad20f20ecdf1b51d7ff359c5c26481201fc
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5B4 3064 bytes