Malicious PDF — malware analysis report

Static analysis result for SHA-256 396e70ff5c0062f1…

MALICIOUS

PDF

21.8 KB Created: 2020-03-19 03:40:52 +00:00 Authoring application: mPDF 5.7
MD5: abe3d11af3960bf9b05bf31e88796373 SHA-1: 57f62e4e0a334f34d1d46e0518a53f2ff0b43aa8 SHA-256: 396e70ff5c0062f16c24df867d76b1d0a206d82eb20b3e7c118441b5c32c9d84
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is a PDF document flagged by ClamAV and an ML classifier as malicious. It contains multiple embedded URLs pointing to external resources, suggesting a downloader or droppper functionality. The PDF_URI heuristic specifically identified an external URI, indicating the file's intent to redirect the user to malicious content hosted externally. The presence of these URLs and the high confidence detection scores strongly suggest this PDF is part of a malware distribution chain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 3

  • ClamAV: Pdf.Malware.Agent-9905952-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Malware.Agent-9905952-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/7c05c05c06c08c00/Commentaire-sur-la-Seconde-p-tre-aux-Corinthiens-by-Georges-Godet.pdf
    • http://laoieoa.myhome.cx/6c08c09c08c04c01/L-AUBERGE-DES-VOYAGEURS-by-Alix-Second-.pdf
    • http://laoieoa.myhome.cx/9c09c06c08c06c06/Nana-de-Zola---Incipit-Commentaire-de-texte-by-Virgine-Loriot.pdf
    • http://laoieoa.myhome.cx/7c08c05c01c07c03/Commentaire-D-Iso-dad-de-Merv-Sur-L-Ancien-Testament-II-Exode-Deuteronome-by-C-Van-Den-Eynde.pdf
    • http://laoieoa.myhome.cx/5c02c04c02c06c00/Boule-de-suif-de-Maupassant---D-nouement-Commentaire-de-texte-by-Sophie-Roy-re.pdf
    • http://laoieoa.myhome.cx/7c07c05c00c07c08/Les-Liaisons-dangereuses-de-Choderlos-de-Laclos---Lettre-LXXXI-Commentaire-de-texte-by-Monia-Ouni.pdf
    • http://laoieoa.myhome.cx/7c05c05c05c07c01/Studies-In-The-Old-Testament-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/7c05c05c07c05c00/Etudes-Bibliques-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/7c05c05c06c06c09/Studies-on-the-New-Testament-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/7c05c05c06c07c05/Articles-et-Sermons-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/7c09c05c03c08c03/Darcy-et-Elisabeth-Transcription-du-Film-Orgueil-et-Prejuges-Suivie-d-un-Commentaire-by-Faudrin-Fillol-Miche.pdf
    • http://laoieoa.myhome.cx/9c03c00c02c01/Evolving-Through-Adversity-How-to-Overcome-Obstacles-Discover-Your-Passion-and-Honor-Your-True-Self-by-Seconde-Nimenya.pdf
    • http://laoieoa.myhome.cx/6c08c09c08c04c03/Evolving-Through-Adversity-How-To-Overcome-Obstacles-Discover-Your-Passion-and-Honor-Your-True-Self-by-Seconde-Nimenya.pdf
    • http://laoieoa.myhome.cx/7c05c05c06c08c02/Commentary-on-the-Gospel-of-St-John-1-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/7c05c05c08c01c03/Introduction-to-the-New-Testament-Volume-1-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/7c05c05c06c02c09/Commentary-on-St-Paul-s-First-Epistle-to-the-Corinthians-Vol-1-by-F-Godet.pdf
    • http://laoieoa.myhome.cx/7c05c05c05c06c07/A-Commentary-on-the-Gospel-of-St-Luke-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/9c01c02c04c06c01/Etre-Juif-En-France-Pendant-La-Seconde-Guerre-Mondiale-L-histoire-En-Marche-by-Renee-Poznanski.pdf
    • http://laoieoa.myhome.cx/7c05c05c05c07c05/A-Commentary-On-The-Gospel-Of-St-Luke-Volume-I-by-Fr-d-ric-Godet.pdf
    • http://laoieoa.myhome.cx/6c01c02c00c04c00/Les-Magistrats-Des-Cites-Italiennes-de-La-Seconde-Guerre-Punique-a-Auguste-Le-Latium-Et-La-Campanie-by-Mireille-Cebeillac-Gervasoni.pdf