Malicious PDF — malware analysis report

Static analysis result for SHA-256 445d631bb12bf22b…

MALICIOUS

PDF

23.0 KB Created: 2020-03-18 21:29:46 +00:00 Authoring application: mPDF 5.7
MD5: bfca2d7369c59933590884a00f6748ea SHA-1: 63cf656773a0c154ef14d27d724e608b08c05f84 SHA-256: 445d631bb12bf22b4df6353460044b03662a23469ae6ec2dac93a89cbe09e701
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

This PDF file was flagged by ClamAV as Pdf.Dropper.Agent-7692915-0 and a machine learning classifier. It contains multiple embedded URLs that likely lead to the download of a second-stage payload. The document body itself is obfuscated, but the presence of external URIs strongly suggests a dropper or downloader functionality.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7692915-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7692915-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/16a06a36a56a96a06a5/The-Long-Shadow-of-Small-Ghosts-Murder-and-Memory-in-an-American-City-by-Laura-Tillman.pdf
    • http://rtuninnsi.myhome.cx/86a16a16a1/Cast-Long-Shadows-Ghosts-of-the-Shadow-Market-2-by-Cassandra-Clare.pdf
    • http://rtuninnsi.myhome.cx/26a76a96a96a36a4/The-Love-Pirate-and-the-Bandit-s-Son-Murder-Sin-and-Scandal-in-the-Shadow-of-Jesse-James-by-Laura-James.pdf
    • http://rtuninnsi.myhome.cx/46a46a66a26a26a2/City-of-Ghosts-Downside-Ghosts-3-by-Stacia-Kane.pdf
    • http://rtuninnsi.myhome.cx/16a46a26a16a66a7/Black-in-Selma-The-Uncommon-Life-of-J-L-Chestnut-Jr-Politics-and-Power-in-a-Small-American-City-by-J-L-Chestnut-Jr-.pdf
    • http://rtuninnsi.myhome.cx/26a76a56a66a06a0/American-Genius-A-Comedy-by-Lynne-Tillman.pdf
    • http://rtuninnsi.myhome.cx/86a96a36a26a16a7/Boots-on-the-Ground-by-Dusk-My-Tribute-to-Pat-Tillman-by-Mary-Tillman.pdf
    • http://rtuninnsi.myhome.cx/36a96a06a46a26a9/Laura-in-the-Kitchen-Favorite-Italian-American-Recipes-Made-Easy-by-Laura-Vitale.pdf
    • http://rtuninnsi.myhome.cx/86a56a96a56a46a3/City-of-Light-City-of-Poison-Murder-Magic-and-the-First-Police-Chief-of-Paris-by-Holly-Tucker.pdf
    • http://rtuninnsi.myhome.cx/26a36a86a36a16a1/City-of-Light-City-of-Poison-Murder-Magic-and-the-First-Police-Chief-of-Paris-by-Holly-Tucker.pdf
    • http://rtuninnsi.myhome.cx/26a16a46a46a56a2/Ghosts-of-the-Shadow-Market-by-Cassandra-Clare.pdf
    • http://rtuninnsi.myhome.cx/56a16a36a96a56a0/The-Long-Life-by-Helen-Small.pdf
    • http://rtuninnsi.myhome.cx/66a96a26a06a66a7/Antigone-s-Ghosts-The-Long-Legacy-of-War-and-Genocide-in-Five-Countries-by-Mark-A-Wolfgram.pdf
    • http://rtuninnsi.myhome.cx/86a96a86a46a86a7/Remembering-Viet-Nam-Gustav-Hasford-Ron-Kovic-Tim-O-Brien-and-the-Fabrication-of-American-Cultural-Memory-Gustav-Hasford-Ron-Kovic-Tim-O-Brien-and-the-Fabrication-of-American-Cultural-Memory-by-Regula-Fuchs.pdf
    • http://rtuninnsi.myhome.cx/86a66a96a1/A-Deeper-Love-Ghosts-of-the-Shadow-Market-5-by-Cassandra-Clare.pdf
    • http://rtuninnsi.myhome.cx/46a26a46a86a66a0/A-City-of-Ghosts-Stories-by-Betsy-Phillips.pdf
    • http://rtuninnsi.myhome.cx/16a76a36a36a16a7/Murder-in-the-Vale-The-Ghosts-of-Cardiff-1-by-Michele-E-Gwynn.pdf
    • http://rtuninnsi.myhome.cx/36a36a46a56a56a7/The-Long-Way-to-a-Small-Angry-Planet-Wayfarers-1-by-Becky-Chambers.pdf
    • http://rtuninnsi.myhome.cx/46a26a46a66a3/The-Long-Way-to-a-Small-Angry-Planet-Wayfarers-1-by-Becky-Chambers.pdf
    • http://rtuninnsi.myhome.cx/46a46a26a96a16a8/The-Long-Way-to-a-Small-Angry-Planet-Wayfarers-1-by-Becky-Chambers.pdf
    • http://rtuninnsi.myhome.cx/16a46a26a16a66a7/Black-in-Selma-The-Uncommon-Life-of-J-L-Chestnut-Jr-Politics-and-Power-in-a-Sm