Malicious PDF — malware analysis report

Static analysis result for SHA-256 efcdbcd82cf9c8b4…

MALICIOUS

PDF

54.3 KB Created: 2021-02-28 19:55:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 96c24768a021f03dea44e171859338a7 SHA-1: 8fc5e75dd66ab7d927eab5bfbe8c12c1ebadae85 SHA-256: efcdbcd82cf9c8b43af3a7f87716befef6199ccd35cbdf27679e4274487189ff
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9535

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/award?keyword=ejemplo+de+dialogo+para+ni%25C3%25B1os+de+segundo+grado PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4393644/normal_5fc99c1283ae9.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4385437/normal_5fe4c57a011c0.pdfIn PDF document text
    • https://perutibabejodu.weebly.com/uploads/1/3/6/0/136051808/cdb06.pdfIn PDF document text
    • https://cdn.sqhk.co/kekumumaxow/igdsO9g/63316020206.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4366980/normal_5fed3a03a0a91.pdfIn PDF document text
    • https://rebejudan.weebly.com/uploads/1/3/5/3/135316845/8938329.pdfIn PDF document text
    • https://pozimifekof.weebly.com/uploads/1/3/4/6/134674510/d4773ae7.pdfIn PDF document text
    • http://kigirifaduguv.getenjoyment.net/zudovajej.pdfIn PDF document text
    • https://cdn.sqhk.co/nusatabi/wc5ghcE/matixa.pdfIn PDF document text
    • https://juvetobewuneted.weebly.com/uploads/1/3/3/9/133997509/sepep.pdfIn PDF document text
    • https://cdn.sqhk.co/somisafeg/hhATJ0T/50385081829.pdfIn PDF document text
    • http://xitawefavam.medianewsonline.com/31850591789.pdfIn PDF document text
    • https://cdn.sqhk.co/dafisuwikib/shgmIL2/99785510246.pdfIn PDF document text
    • https://s3.amazonaws.com/bugutaj/98818582101.pdfIn PDF document text
    • https://s3.amazonaws.com/fukepez/beneb.pdfIn PDF document text
    • https://s3.amazonaws.com/kesumasaka/bollywood_movie_posters_hd_free.pdfIn PDF document text
    • http://mekofirudusem.rf.gd/how_many_sweet_potatoes_is_3_lbs.pdfIn PDF document text
    • https://s3.amazonaws.com/minabiwa/d_d_spore_druid_guide.pdfIn PDF document text
    • http://putiremupupunis.epizy.com/83156169901.pdfIn PDF document text