Malicious PDF — malware analysis report

Static analysis result for SHA-256 374ff6914128504d…

MALICIOUS

PDF

17.4 KB Created: 2019-05-02 17:35:00 +01:00 Authoring application: mPDF 5.7
MD5: d1666b62c2dcbcf617554ee3f6d93f05 SHA-1: 16f181ae35fbce73ddcd347449ca3013c8991858 SHA-256: 374ff6914128504d389000b828c5ff612bfc0f67690f0d511358eca99d263cd1
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded URLs that redirect to external resources, indicating a likely distribution or redirection mechanism. ClamAV detection as 'Pdf.Dropper.Agent' and the ML classifier's high confidence score further support its malicious nature. The primary function appears to be directing users to potentially harmful content hosted on 'kiteeearpdf.myhome.cx'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-9257796-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9257796-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/4f217f216f215f212f216/Atonement-Beartooth-Montana-4-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/4f213f213f215f214f214/Mercy-Beartooth-Montana-5-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f216f210/Second-Chance-Cowboy-Whitehorse-Montana-6-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f214f218/Matchmaking-with-a-Mission-Whitehorse-Montana-5-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f218f213f218/One-Hot-Forty-Five-Whitehorse-Montana-The-Corbetts-Book-5-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f215f214f217/Dark-Horse-Whitehorse-Montana-The-McGraw-Kidnapping-1-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f218f213f216/Secret-Of-Deadman-s-Coulee-The-New-Deputy-In-Town-Whitehorse-Montana-Book-1-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f218f214f218/Whitehorse-Montana-The-Clementines-Hard-Rustler-Rogue-Gunslinger-Rugged-Defender-by-B-J-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/1f214f217f219f213f214/Six-Months-in-Montana-Montana-Sweet-Western-Romance-1-by-Pamela-M-Kelley.pdf
    • http://kiteeearpdf.myhome.cx/2f218f212f215f215f216/Six-Months-in-Montana-Montana-Sweet-Western-Romance-1-by-Pamela-M-Kelley.pdf
    • http://kiteeearpdf.myhome.cx/2f213f213f216f218f211/Wild-Montana-Skies-Montana-Rescue-1-by-Susan-May-Warren.pdf
    • http://kiteeearpdf.myhome.cx/2f212f217f218f214f216/Montana-Rose-Montana-Marriages-1-by-Mary-Connealy.pdf
    • http://kiteeearpdf.myhome.cx/4f219f215f211f219f218/Montana-At-Sunrise-The-Montana-Brides-1-by-Blaire-Brand.pdf
    • http://kiteeearpdf.myhome.cx/1f210f214f215f214f210f219/Daniels-Running-Formula-by-Jack-Daniels.pdf
    • http://kiteeearpdf.myhome.cx/4f211f214f214f210f213/Montana-Sky-Christmas-Montana-Sky-3-1-by-Debra-Holland.pdf
    • http://kiteeearpdf.myhome.cx/1f211f214f211f212/One-Night-with-Her-Bachelor-Wild-Montana-Nights-1-Montana-Born-Bachelor-Auction-6-by-Kat-Latham.pdf
    • http://kiteeearpdf.myhome.cx/1f212f218f218f212f211/A-Kate-Daniels-Magic-Series-Collection-Kate-Daniels-1-5-by-Ilona-Andrews.pdf
    • http://kiteeearpdf.myhome.cx/1f213f214f219f214f215/Montana-Marriages-Trilogy-Montana-Marriages-1-3-by-Mary-Connealy.pdf
    • http://kiteeearpdf.myhome.cx/4f217f212f219f211f213/Atonement-by-Ian-McEwan.pdf
    • http://kiteeearpdf.myhome.cx/4f212f211f216f214f211/Atonement-by-Ian-McEwan.pdf
    • http://kiteeearpdf.myhome.cx/7f217f216f218f214f218/Whitehorse-Montana-The-Clementines-Hard-Rustler-Rogue-Gunslinger-Rugged-Defender-by-B-J-D