Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb89521fa043aeee…

MALICIOUS

PDF

49.6 KB Created: 2021-03-24 17:09:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 0eca9ca2a0bb8e55396ef3dcb3c2bb68 SHA-1: 6b3e70cdf8ad81b8809270304e0f52e297d41526 SHA-256: eb89521fa043aeeeb969f45728e39eb8a7454cc9567e4aa20146f6a54a7aab6f
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6303

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/aws?utm_term=cuento+el+principito+resumen+pdf PDF link annotation
    • http://sexesex.site/stihl_trimmers_batteryuqrie.pdfIn PDF document text
    • http://maddot.space/52998647596eri5p.pdfIn PDF document text
    • http://nibajafij.medianewsonline.com/can_i_get_disney_on_samsung_smart_tv.pdfIn PDF document text
    • http://apelsins.space/wahl_trimmer_battery_745-8000jpu1.pdfIn PDF document text
    • http://nenegifivujaxu.mypressonline.com/does_the_keurig_2.0_k500_have_a_water_filter.pdfIn PDF document text
    • http://dedigevobunobe.medianewsonline.com/amazon_kindle_ebook_reader.pdfIn PDF document text
    • http://sumapewub.getenjoyment.net/allopathic_medicine_book_free_download.pdfIn PDF document text
    • https://s3.amazonaws.com/dagasopones/lopesim.pdfIn PDF document text
    • https://s3.amazonaws.com/bidemewufa/azhar_full_hd_video_song.pdfIn PDF document text
    • http://panexorumilogim.myartsonline.com/why_is_the_brother_printer_not_printing.pdfIn PDF document text
    • https://s3.amazonaws.com/dufekifaral/95369201036.pdfIn PDF document text
    • https://s3.amazonaws.com/tufujifinobiro/gta_san_andreas_cheats_pc_superman_cheat_codes.pdfIn PDF document text