Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff5766028c7a6aff…

MALICIOUS

PDF

58.4 KB Created: 2021-06-12 09:24:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: d9792b114b78165d042ff8c5a699123b SHA-1: b94d00aa6266ce9b8ded5559a2b8deddc7323c61 SHA-256: ff5766028c7a6aff13bfd427504ea283692df90864b2f40257e5f32a4dd2a928
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing an embedded URI that points to a suspicious URL. The ClamAV detection and ML classifier indicate malicious intent. The document body, though heavily obfuscated, contains text related to 'torrent' which aligns with the URL's apparent lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7169

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nomylo.ru/uplcv?utm_term=dumb+and+dumber+to+torrent PDF link annotation