Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a70363be7f4b9ff…

MALICIOUS

PDF

16.6 KB Created: 2019-05-07 06:13:21 +01:00 Authoring application: mPDF 5.7
MD5: 48d5f97f03fe6fcec6fc612855cd9d94 SHA-1: 5090d317bc343231647e9437bb0f8ac0d2b10d40 SHA-256: 4a70363be7f4b9ffdfe4e523d96bfdf37d28ab60fff93c1f546ddf63ce194d52
70 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified as a PDF dropper by ClamAV. It contains embedded URLs that appear to be download links for documents, but the heuristic indicates a call-to-action lure. The primary URL, http://muicuiu.dumb1.com/8a06a02a08a08/On-the-Natural-History-of-Destruction-by-W-G-Sebald.pdf, is likely used to deliver a secondary payload. The document body contains obfuscated text and repeated URLs, further suggesting a malicious intent to trick the user into downloading content.

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7143016-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7143016-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://muicuiu.dumb1.com/8a06a02a08a08/On-the-Natural-History-of-Destruction-by-W-G-Sebald.pdf
    • http://muicuiu.dumb1.com/1a01a00a00a09a09a06/Adolescence-gt-Custom-lt-Author-Sebald-Publisher-Pearson-C-by-Sebald.pdf
    • http://muicuiu.dumb1.com/8a09a02a00a03a00/Searching-for-Sebald-Photography-After-W-G-Sebald-by-Lise-Patt.pdf
    • http://muicuiu.dumb1.com/6a03a03a05a01/Dialogues-Concerning-Natural-Religion-and-The-Natural-History-of-Religion-by-David-Hume.pdf
    • http://muicuiu.dumb1.com/5a08a06a04a03a06/Infancy-and-History-On-the-Destruction-of-Experience-by-Giorgio-Agamben.pdf
    • http://muicuiu.dumb1.com/3a03a08a02a03a03/Wave-of-Destruction-The-Stories-of-Four-Families-and-History-s-Deadliest-Tsunami-by-Erich-Krauss.pdf
    • http://muicuiu.dumb1.com/1a03a08a05a02a00/Natural-Right-and-History-by-Leo-Strauss.pdf
    • http://muicuiu.dumb1.com/8a08a08a05a06a03/Why-We-Run-A-Natural-History-by-Bernd-Heinrich.pdf
    • http://muicuiu.dumb1.com/4a07a01a04a01a09/A-Natural-History-of-Wine-by-Ian-Tattersall.pdf
    • http://muicuiu.dumb1.com/2a05a00a06a07a00/Why-We-Run-A-Natural-History-by-Bernd-Heinrich.pdf
    • http://muicuiu.dumb1.com/3a09a06a00a08a01/Natural-History-A-Selection-by-Pliny-the-Elder.pdf
    • http://muicuiu.dumb1.com/6a09a07a05a05a08/Walking-with-Dinosaurs-A-Natural-History-by-Tim-Haines.pdf
    • http://muicuiu.dumb1.com/6a09a00a02a07a03/The-Natural-History-of-Unicorns-by-Chris-Lavers.pdf
    • http://muicuiu.dumb1.com/4a04a07a06a03a08/The-Natural-History-of-Canterbury-by-Michael-Winterbourn.pdf
    • http://muicuiu.dumb1.com/1a01a02a00a05a07/The-Gal-pagos-A-Natural-History-by-Henry-Nicholls.pdf
    • http://muicuiu.dumb1.com/1a04a04a05a02a04/Sahara-A-Natural-History-by-Marq-de-Villiers.pdf
    • http://muicuiu.dumb1.com/1a08a08a00a05a02/Natural-History-of-New-York-by-John-Kieran.pdf
    • http://muicuiu.dumb1.com/2a05a08a02a09/A-Natural-History-of-Hell-by-Jeffrey-Ford.pdf
    • http://muicuiu.dumb1.com/2a03a09a04a02a01/Ebola-The-Natural-and-Human-History-by-David-Quammen.pdf
    • http://muicuiu.dumb1.com/8a00a00a06a04a08/Pastorale-A-Natural-History-of-Sorts-by-Jake-Page.pdf