Malicious PDF — malware analysis report

Static analysis result for SHA-256 f15367f466188434…

MALICIOUS

PDF

55.7 KB Created: 2021-09-04 21:05:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-14
MD5: 91092c08f313411d0251194f0b5af808 SHA-1: 679621b4330bf12e6cdeeb993ba228f77c5d1175 SHA-256: f15367f46618843400c809b60df98bc86f19eb64a345ba077396b955315f982f
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating the presence of external URIs and embedded URLs. The document body, though heavily obfuscated, suggests it is a PDF generated by wkhtmltopdf. The primary attack vector appears to be social engineering, luring the user with a deceptive title related to forex education to download a malicious PDF. The embedded URLs likely serve as download locations for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5090

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://agermag.ro/mm/file/pafapatukufabudolibosul.pdf In PDF document text
    • https://bocion.com/ckfinder/userfiles/files/kotabunajixobokep.pdfIn PDF document text
    • http://altelaw.com/uploads/image/file/24685585574.pdfIn PDF document text
    • http://nuitsdartistes.eu/images/file/35134328230.pdfIn PDF document text
    • http://gennarimaq.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16102bbf768d0e---47590331993.pdfIn PDF document text
    • https://poolpoint.be/uploads/file/wuwenetevefadozow.pdfIn PDF document text
    • http://andreagarciam.com/wp-content/plugins/formcraft/file-upload/server/content/files/1610d8e589676a---75805974310.pdfIn PDF document text
    • http://stl-hk.net/In PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/BkSY9tpko7c/uplcv?utm_term=xm+forex+education+pdfPDF link annotation