Malicious PDF — malware analysis report

Static analysis result for SHA-256 52e426ab04af0c6e…

MALICIOUS

PDF

18.4 KB Created: 2020-02-14 19:28:08 +00:00 Authoring application: mPDF 5.7
MD5: c02de33cfaa6c18ed22c801986185d44 SHA-1: 2ce8834d1d69febcf81a4ee5babd025b391bdbd0 SHA-256: 52e426ab04af0c6e1dbf2acdbb27126938117795966eac17af2a7e6ed7b64dcd
70 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file was detected as Pdf.Dropper.Agent-8798939-0 by ClamAV, indicating it functions as a dropper. The presence of a visual download button and numerous embedded URLs pointing to PDF files suggests a social engineering lure to trick users into downloading further malicious content. The document body, though heavily obfuscated, contains references to these URLs, reinforcing the dropper functionality.

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-8798939-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-8798939-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ujcsiniio.myhome.cx/9cd8cd4cd4cd9cd3/Von-G-ttern-und-D-monen-Satans-Tochter-by-S-Horvath.pdf
    • http://ujcsiniio.myhome.cx/9cd4cd3cd1cd9cd6/Endlich-frei-Ich-bin-die-Tochter-aus-quot-Nicht-ohne-meine-Tochter-quot-Hier-ist-die-ganze-Geschichte-by-Mahtob-Mahmoody.pdf
    • http://ujcsiniio.myhome.cx/9cd2cd9cd9cd7cd6/Satans-of-Saturn-by-Otis-Adelbert-Kline.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd4cd0cd5cd0cd2/Dreizack-Das-Zeichen-des-Satans-by-Ralf-Kelten.pdf
    • http://ujcsiniio.myhome.cx/5cd3cd7cd0cd6cd8/John-Sinclair---Folge-0126-Satans-Razzia-by-Jason-Dark.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd4cd3cd4cd2cd9/Australien-Nach-Dem-Stande-Der-Geographischen-Kenntniss-in-1871-Vol-2-Nach-Originalen-Und-Offiziellen-Quellen-Kartographisch-Nebst-Einem-Geographisch-Statistischen-Compendium-Die-S-dh-lfte-Australiens-in-4-Kartenbl-ttern-by-August-Petermann.pdf
    • http://ujcsiniio.myhome.cx/4cd4cd5cd9cd4cd2/Understories-by-Tim-Horvath.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd7cd8cd5cd4cd0/Tochter-des-Flusses-by-Dana-Graham.pdf
    • http://ujcsiniio.myhome.cx/1cd5cd0cd2cd0/The-Trolls-by-Polly-Horvath.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd7cd7cd6cd5cd5/SCHMERZ-Meine-Tochter-by-Breena-Eckert.pdf
    • http://ujcsiniio.myhome.cx/8cd9cd3cd1cd5cd1/T-chter-der-See-Irland-Trilogie-3-by-Nora-Roberts.pdf
    • http://ujcsiniio.myhome.cx/9cd9cd7cd9cd8cd1/Rund-um-den-Kongre-by-d-n-von-Horv-th.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd4cd3cd4cd6cd5/Autobiographisches-und-Theoretisches-by-d-n-von-Horv-th.pdf
    • http://ujcsiniio.myhome.cx/3cd0cd6cd6cd2/The-Canning-Season-by-Polly-Horvath.pdf
    • http://ujcsiniio.myhome.cx/4cd5cd6cd0cd5cd1/When-the-Circus-Came-to-Town-by-Polly-Horvath.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd1cd8cd9cd3cd5/Die-s-e-Tochter-der-Nachbarn---Erwischt-und-vernascht-by-Honey-Bee.pdf
    • http://ujcsiniio.myhome.cx/6cd7cd5cd6cd2cd1/Pynchon-and-Mason-amp-Dixon-by-Brooke-Horvath.pdf
    • http://ujcsiniio.myhome.cx/1cd1cd9cd4cd1cd1cd5/Hin-Und-Her-Posse-in-Zwei-Teilen-by-d-n-von-Horv-th.pdf
    • http://ujcsiniio.myhome.cx/4cd8cd1cd8cd5cd1/Dig-Dogs-Dig-A-Construction-Tail-by-James-Horvath.pdf
    • http://ujcsiniio.myhome.cx/9cd8cd4cd5cd7cd9/Von-G-ttern-und-D-monen-Nagars-R-ckkehr-by-S-Horvath.pdf
    • http://ujcsiniio.myhome.cx/1cd0cd4cd3cd4cd2cd9/Australien-Nach-Dem-Stande-Der-Geographischen-Kenntniss-in-1871-Vol-2-Nach-Originalen-Und-Offiziellen-Quellen-Kartographisch-Nebst-Einem-Geographisch-Statistischen-Compend