Malicious PDF — malware analysis report

Static analysis result for SHA-256 04e7f97aba8322a6…

MALICIOUS

PDF

36.7 KB Created: 2019-04-30 04:34:38 +01:00 Authoring application: mPDF 5.7
MD5: 3c4c8b1d5d899b3f4c54c689db597df7 SHA-1: 69cdfd0bda3d2096056860d071dc7df86cf84564 SHA-256: 04e7f97aba8322a6922bc1dcaab9ed0c60bbf6a42f666b6c622dd70368be917c
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF containing embedded URLs that mimic book titles, likely as a lure to trick users into downloading malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URLs, such as http://seasasac.lflinkup.com/3da8da3da1da1da6/Panzer-Aces-II-Battle-Stories-of-German-Tank-Commanders-in-World-War-II-by-Franz-Kurowski.pdf, are the primary indicators of this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9656

Heuristics 3

  • ClamAV: Pdf.Malware.Agent-9973071-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Malware.Agent-9973071-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/3da8da3da1da1da6/Panzer-Aces-II-Battle-Stories-of-German-Tank-Commanders-in-World-War-II-by-Franz-Kurowski.pdf
    • http://seasasac.lflinkup.com/8da8da0da8da8da4/Elite-Panzer-Strike-Force-Germany-s-Panzer-Lehr-Division-in-World-War-II-by-Franz-Kurowski.pdf
    • http://seasasac.lflinkup.com/8da9da5da7da5da5/Erwin-Rommel-and-Heinz-Guderian-The-Lives-and-Careers-of-Nazi-Germany-s-Legendary-Tank-Commanders-by-Charles-River-Editors.pdf
    • http://seasasac.lflinkup.com/9da4da1da0da7da3/Panzer-Tactics-German-Small-Unit-Armor-Tactics-in-World-War-II-by-Wolfgang-Schneider.pdf
    • http://seasasac.lflinkup.com/1da1da8da3da0da9da3/Learn-German-with-Stories-Dino-lernt-Deutsch-Collector-s-Edition---German-Short-Stories-for-Beginners-Explore-German-Cities-and-Boost-Your-Vocabulary-by-Andr-Klein.pdf
    • http://seasasac.lflinkup.com/8da9da5da7da5da2/Guderian-Myth-of-Blitzkrieg-and-Panzer-Tactics-by-The-German-Army-Publications.pdf
    • http://seasasac.lflinkup.com/8da9da5da7da5da0/Guderian-Panzer-s-on-War-1939-1941-by-German-Military-Books-2000--2015.pdf
    • http://seasasac.lflinkup.com/3da6da6da6da7da4/Hitler-Victorious-Eleven-Stories-of-the-German-Victory-in-World-War-II-by-Gregory-Benford.pdf
    • http://seasasac.lflinkup.com/1da0da8da7da0da6da1/Focus-On-30-Most-Popular-Battles-of-World-War-II-Involving-the-United-States-Battle-of-Iwo-Jima-Omaha-Beach-Battle-of-Anzio-Battle-of-H-rtgen-Forest-in-Italy-Operation-Nordwind-etc-by-Wikipedia-contributors.pdf
    • http://seasasac.lflinkup.com/9da8da7da1da6da9/World-War-2-Waffen-SS-Soldier-Stories-Eyewitness-Accounts-of-Hitler-s-Elite-Troops-Waffen-SS-World-War-2-WW2-WWII-German-Soldiers-Hitler-by-Ryan-Jenkins.pdf
    • http://seasasac.lflinkup.com/8da9da5da7da5da3/Guderian-s-Xixth-Panzer-Corps-and-the-Battle-of-France-Breakthrough-in-the-Ardennes-May-1940-by-Florian-K-Rothbrust.pdf
    • http://seasasac.lflinkup.com/1da0da3da6da5da8da9/Learn-German-with-Literature-Immensee-by-Theodor-Storm-Interlinear-German-to-English-Learn-German-with-Interlinear-Stories-for-Beginners-and-Advanced-Readers-Book-4-by-Kees-Van-den-End.pdf
    • http://seasasac.lflinkup.com/9da4da0da8da5da4/Panzer-Ace-The-Memoirs-of-an-Iron-Cross-Panzer-Commander-from-Barbarossa-to-Normandy-by-Richard-Freiherr-von-Rosen.pdf
    • http://seasasac.lflinkup.com/9da4da1da1da8da2/Germany-s-Panzer-Arm-in-World-War-II-by-Richard-L-DiNardo.pdf
    • http://seasasac.lflinkup.com/3da7da1da6da7da2/Spearhead-An-American-Tank-Gunner-His-Enemy-and-a-Collision-of-Lives-In-World-War-II-by-Adam-Makos.pdf
    • http://seasasac.lflinkup.com/9da2da4da6da5da9/FRANZ-KAFKA---SAEMTLICHE-WERKE-FRANZ-KAFKA---GESAMTAUSGABE-Band-I-DER-BESTSELLER-Meisterwerke-von-Franz-Kafka---Der-Prozess-Die-Verwandlung-In-der-Strafkolonie-Das-Schloss-Amerika-UND-MEHR---IN-EINEM-BAND-FRANZ-KAFKA-Illustriert-Nook-NOOKbook-by-Franz-Kafka.pdf
    • http://seasasac.lflinkup.com/4da3da2da8da3da5/The-First-Eagles-The-American-Pilots-Who-Flew-With-the-British-Became-Aces-and-Won-World-War-I-by-Gavin-Mortimer.pdf
    • http://seasasac.lflinkup.com/1da0da3da5da5da9da6/Stalin-s-Eagles-An-Illustrated-Study-of-the-Soviet-Aces-of-the-World-War-II-and-Korea-by-Hans-D-Seidl.pdf
    • http://seasasac.lflinkup.com/4da8da8da3da9da6/Learn-German-with-Stories-Ahoi-Aus-Hamburg---10-Short-Stories-for-Beginners-by-Andr-Klein.pdf
    • http://seasasac.lflinkup.com/6da0da3da0da8da4/Learn-German-With-Stories-Caf-in-Berlin---10-Short-Stories-For-Beginners-by-Andr-Klein.pdf