Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed292c2406ab3ce4…

MALICIOUS

PDF

59.9 KB Created: 2021-03-02 15:24:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-17
MD5: 13ea29c8a8435a939a31a27d92d6ac68 SHA-1: d6aee7cec7f8d3efc08d321bd1a3b43100fc7f48 SHA-256: ed292c2406ab3ce44ab807735ed809d036237a1bbb6246a8314e998174c1de07
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to metal detectors, aiming to trick users into clicking the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7054

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/award?keyword=how+to+ground+balance+a+garrett+ace+400 PDF link annotation
    • https://cdn.sqhk.co/lakivasulis/idGhgzE/48254747730.pdfIn PDF document text
    • https://cdn.sqhk.co/zalivelo/hell3jg/jw_library_para_macbook.pdfIn PDF document text
    • https://cdn.sqhk.co/zasemewiti/eJmcV4E/29870459405.pdfIn PDF document text
    • https://cdn.sqhk.co/vumusokutil/Ejf7aib/exploding_kittens_playing_cards.pdfIn PDF document text
    • https://cdn.sqhk.co/fewoxenovof/pihpgjn/real_bike_racing_happymod.pdfIn PDF document text
    • http://icub.tech/architectural_home_design_software_freeh0h30.pdfIn PDF document text
    • http://copytoshka.ru/xanowejiwazeqyj.pdfIn PDF document text
    • http://dlkmvkoenv.info/casio_g_shock_rangeman_replacement_bandhk8u2.pdfIn PDF document text
    • http://fortuneocredit.com/27542694745w6cjw.pdfIn PDF document text
    • https://cdn.sqhk.co/nerurepaza/kNggole/download_flippy_bottle_extreme.pdfIn PDF document text
    • https://cdn.sqhk.co/wodaximewule/gebzcib/project_drift_unlimited_money.pdfIn PDF document text
    • https://cdn.sqhk.co/wujakegu/eTjjRbl/blue_flag_with_yellow_star_and_red_stripe.pdfIn PDF document text
    • https://s3.amazonaws.com/rafiralexezol/marine_biogeography.pdfIn PDF document text
    • https://s3.amazonaws.com/ravuxudibure/visual_identity_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/poresi/gypsy_moth_life_cycle_michigan.pdfIn PDF document text
    • https://s3.amazonaws.com/dogazisuze/hindu_god_name_list.pdfIn PDF document text
    • https://s3.amazonaws.com/susonanezaj/12049256520.pdfIn PDF document text