Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2bc78376e3a4cdb…

MALICIOUS

PDF

52.6 KB Created: 2021-09-20 07:13:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-11-25
MD5: ccdbb2bbbb27cfb2466a1d7112f214b7 SHA-1: d825c10af644c94b789a4b148b5df95bcb0789aa SHA-256: e2bc78376e3a4cdbd2ef19cf804e8cc3f39f0938e78c5f409b5e22f1c7511f20
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV with a specific signature indicating it is a phishing trojan. The embedded URI points to a URL that mimics a firmware download search result, strongly suggesting a phishing or malware distribution attempt. While no scripts were explicitly extracted, the PDF structure and embedded URI indicate a malicious intent to redirect users to a potentially harmful site.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4747

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://chcial.ru/uplcv?utm_term=samsung+galaxy+grand+prime+firmware+download PDF link annotation
    • http://word.mn/uploads/assets/rimovada.pdfIn PDF document text
    • https://dienhoanghean.com/upload/ck/files/vuzitixamowumile.pdfIn PDF document text
    • http://bakineshr.az/ckfinder/userfiles/files/94587477840.pdfIn PDF document text
    • https://jlgardner.org/home/jlg/public_html/ckfinder/userfiles/files/fivojubukezivewivofavu.pdfIn PDF document text
    • http://sgpeo.pl/users/file/35522653259.pdfIn PDF document text
    • http://appartenvue.net/appart/upload/images/jovoxujutoselokufek.pdfIn PDF document text
    • http://cuacuonanbinh.com/userfiles/file/vebikizupoludadibelubuke.pdfIn PDF document text