Malicious PDF — malware analysis report

Static analysis result for SHA-256 010591ffd900b62d…

MALICIOUS

PDF

18.9 KB Created: 2019-05-02 17:59:20 +01:00 Authoring application: mPDF 5.7
MD5: d42f9ff2e7cd268fb6a770a1fad511ea SHA-1: 739b58bc3105f2baae43c503ca9f94d5f2b6a330 SHA-256: 010591ffd900b62d6de292b46cc5ec8cfb44df99e59fc59ffcf6dd52d4141f5e
94 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded URLs that point to external resources, identified by the PDF_URI heuristic. The ClamAV detection as 'Pdf.Dropper.Agent-7156957-0' and the ML classifier's high confidence score indicate malicious intent. The embedded URLs likely serve as a lure to download a second-stage payload, disguised as legitimate documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7156957-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7156957-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e14e14e04e94e14e5/Bettgefl-ster-Die-besten-Kommunikationstipps-f-r-Paare-by-Andrea-Br-u.pdf
    • http://unieoooq.linkpc.net/94e64e54e34e54e4/Brot-backen-mit-N-ssen-amp-K-rnern---Die-besten-Rezepte-f-r-Anf-nger-und-Fortgeschrittene-Das-Rezeptbuch---Selber-backen-f-r-Genie-er---Brot-backen-in-Perfektion---die-besten-Rezepte-31-by-Al-na-nn.pdf
    • http://unieoooq.linkpc.net/84e64e04e84e04e7/Paare-by-Roland-E-Koch.pdf
    • http://unieoooq.linkpc.net/84e64e04e94e04e9/Beziehungsweise-Sex-Tipps-f-r-Paare-by-Dirk-Ludigs.pdf
    • http://unieoooq.linkpc.net/84e64e04e84e54e5/Perspektiven-Fur-Erwachsene-Paare-by-Anna-Schoch.pdf
    • http://unieoooq.linkpc.net/84e64e04e94e64e7/Wunschkinder---F-r-lesbische-Paare-mit-Kinderwunsch-by-Hannah-Schulte.pdf
    • http://unieoooq.linkpc.net/84e64e04e84e24e2/Die-geheime-Sprache-gl-cklicher-Paare-by-Bill-Farrel.pdf
    • http://unieoooq.linkpc.net/84e64e04e84e64e8/Mutter-Tochter-Paare-in-Der-Hexenverfolgung-by-Lydia-Peters.pdf
    • http://unieoooq.linkpc.net/84e64e04e94e74e8/Liebevolle-Partnerschaft-Gewaltfreie-Kommunikation-f-r-Paare-by-Ronald-Hempel.pdf
    • http://unieoooq.linkpc.net/84e64e04e94e44e3/Paare-in-Krisen-Navigationshilfe-f-r-schwieriges-Gel-nde-by-Reinhardt-Kr-tzig.pdf
    • http://unieoooq.linkpc.net/84e64e04e94e14e3/Geniale-Beziehungen-Ber-hmte-Paare-In-Der-Wissenschaft-by-Ulla-F-lsing.pdf
    • http://unieoooq.linkpc.net/84e64e04e94e74e5/Wenn-Paare-Unternehmen-f-hren-Ein-Handbuch-by-Lianne-Fravi.pdf
    • http://unieoooq.linkpc.net/84e64e04e94e44e4/Partnertausch-20-Paare-gestehen-ihre-scharfen-Swingererlebnisse-by-Hugh-Lorenz.pdf
    • http://unieoooq.linkpc.net/14e14e34e74e14e34e3/Das-Verzeihen-in-der-Liebe-Wie-Paare-neue-N-he-finden-by-Michael-C-llen.pdf
    • http://unieoooq.linkpc.net/14e14e94e14e54e04e2/Stories-Untold-Jewish-Pioneer-Women-1850-1910-The-Art-of-Andrea-Kalinowski-by-Andrea-Kalinowski.pdf
    • http://unieoooq.linkpc.net/14e14e74e74e44e44e1/Beziehung-Und-Bezauberungwie-Paare-Sich-Verlieren-Und-Wiederfinden-Gespiegelt-In-M-rchen-Und-Mythen-by-Hans-Jellouschek.pdf
    • http://unieoooq.linkpc.net/94e44e54e94e44e6/Chi-Ha-Paura-Designers-on-Jewellery-by-Liesbeth-den-Besten.pdf
    • http://unieoooq.linkpc.net/94e34e84e34e54e6/Zucchini-Tomaten-Melanzane-Die-besten-Rezepte-by-Karin-Longariva.pdf
    • http://unieoooq.linkpc.net/14e14e34e34e74e64e4/Vorsicht-Betr-ger---Die-besten-Tricks-der-Trickbetr-ger-Leseprobe-XXL-by-W-Ratz.pdf
    • http://unieoooq.linkpc.net/94e24e04e84e04e4/Die-besten-Bilder-von-nackten-M-dchen-2-200-sexbilder-by-Tomas-Butter.pdf