Malicious PDF — malware analysis report

Static analysis result for SHA-256 e05f73f744017214…

MALICIOUS

PDF

56.4 KB Created: 2021-05-06 12:06:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2ff85e8cde020b21b222177cc431bada SHA-1: 71a535ae43435737ca7750dc9fe88cfb8b61f23f SHA-256: e05f73f7440172147f37218abeb098240b041731a3409f33e8b24e4f6b0c9dc8
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains embedded URLs and was flagged by multiple detection engines as malicious, including ClamAV identifying it as a phishing trojan. The document body, though heavily obfuscated, suggests a lure related to 'Obamacare income limits 2019 chart pdf'. The presence of embedded URLs indicates an attempt to redirect the user to malicious content, likely for phishing or to download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7674

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://arizonalightingsales.com/wp-content/plugins/super-forms/uploads/php/files/5c6cdc26db1fd4165a424d7f67973a8b/52723684386.pdf
    • http://lifemartrealestateconnect.com/wp-content/plugins/super-forms/uploads/php/files/m5jtuhnlfn6pmflb0nitb31471/67576945180.pdf
    • https://www.mii.net/wp-content/plugins/super-forms/uploads/php/files/e4dd8f6ff1579c9ee113b7228358dee8/80763669656.pdf
    • http://azizolace.cz/images/file/kosonotenifitetog.pdf
    • https://www.dekleinewerf.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607bdaf830d44---89330950518.pdf
    • http://pck.malopolska.pl/wp-content/plugins/super-forms/uploads/php/files/c6d40ec055897d48b92dc33a7a299384/vitoxaxuxesefizasema.pdf
    • http://amtusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607595c80730a---sepuzigunuwonu.pdf
    • https://atlanthealth.com/wp-content/plugins/super-forms/uploads/php/files/bfd5b9320e42ab3baad7f85318680cf6/talan.pdf
    • https://inlandautorepairmurrietaca.com/wp-content/plugins/super-forms/uploads/php/files/b326cbca784ebcb70251e9a51f95c888/vuzem.pdf
    • https://www.andeanskyline.com/wp-content/plugins/formcraft/file-upload/server/content/files/160928cc4dc971---62252474331.pdf
    • http://gtshotel.it/images/file/60576086683.pdf
    • https://craftsmancuttingdies.com/wp-content/plugins/super-forms/uploads/php/files/3d89d0e696e10f799b9ad813bc2d1202/63320222588.pdf
    • http://structurecreative.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608fd41a8e0c1---tavajebinurug.pdf
    • http://www.cuadernos.in/wp-content/plugins/formcraft/file-upload/server/content/files/1608f5c70d0366---72978852923.pdf
    • https://www.charityweiss.de/wp-content/plugins/formcraft/file-upload/server/content/files/1606d0fb20f782---36749540018.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=obamacare+income+limits+2019+chart+pdf
    • https://bxthirteen.wpengine.com/wp-content/plugins/super-forms/uploads/php/files/c1166430bca5a55cdb6f28f567e5eb1d/38096150937.pdf