Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c8a2c31aa31d218…

MALICIOUS

PDF

17.1 KB Created: 2019-05-02 19:22:53 +01:00 Authoring application: mPDF 5.7
MD5: 25a3d1587c1b2acc9cf5be82c4cb90e6 SHA-1: b4cac9398d21c6033439edd3478d955c68f1ba56 SHA-256: 7c8a2c31aa31d21837ebf182ea74a2b8a2520f9ef4f1ee377ed8051bf31cc67e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple embedded URLs that are disguised as book titles, aiming to trick the user into downloading a malicious file. The ClamAV detection and ML classifier strongly indicate malicious intent, consistent with a dropper or downloader. The embedded URLs are the primary indicators of compromise, likely leading to further stages of infection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7202993-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7202993-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/2f212f213f213f215f212/Sophie-s-Bakery-for-the-Broken-Hearted-by-Lolly-Winston.pdf
    • http://kiteeearpdf.myhome.cx/3f216f211f217f216/Good-Grief-by-Lolly-Winston.pdf
    • http://kiteeearpdf.myhome.cx/2f217f214f212f214f218/Close-To-the-Broken-Hearted-by-Michael-Hiebert.pdf
    • http://kiteeearpdf.myhome.cx/4f210f218f210f214f212/Swahili-for-the-Broken-Hearted-by-Peter-Moore.pdf
    • http://kiteeearpdf.myhome.cx/4f219f211f217f215f213/Broken-Hearted-Ghoul-Taxi-for-the-Dead-1-by-Joyce-Lavene.pdf
    • http://kiteeearpdf.myhome.cx/4f219f210f218/Cold-Hearted-Hearted-1-by-Winter-Renshaw.pdf
    • http://kiteeearpdf.myhome.cx/7f215f219f210f218f211/The-Complete-Magnolia-Bakery-Cookbook-Recipes-from-the-World-Famous-Bakery-and-Allysa-Torey-s-Home-Kitchen-by-Jennifer-Appel.pdf
    • http://kiteeearpdf.myhome.cx/7f219f210f218f214f219/Winston-s-War-Winston-Churchill-1-by-Michael-Dobbs.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f218f213f216f215/The-Halfbreed-Jeb-Winston-Armistead-by-Bobby-Winston.pdf
    • http://kiteeearpdf.myhome.cx/4f211f212f216f214f213/Lucky-Day-In-Between-2-by-Lolly-Pope.pdf
    • http://kiteeearpdf.myhome.cx/7f219f210f219f219f218/Winston-Churchill-The-Incredible-Life-And-Legacy-Of-Winston-Churchill-by-Tom-King.pdf
    • http://kiteeearpdf.myhome.cx/4f213f219f217f219f213/Lolly-Luck-by-Ellie-Daines.pdf
    • http://kiteeearpdf.myhome.cx/2f215f210f216f213f219/Lolly-Willowes-by-Sylvia-Townsend-Warner.pdf
    • http://kiteeearpdf.myhome.cx/2f217f219f211f214f214/Sky-Ray-Lolly-Abacus-Books-by-Fiona-Pitt-Kethley.pdf
    • http://kiteeearpdf.myhome.cx/5f218f216f218f213f217/Nothing-Stopped-Sophie-The-Story-of-Unshakable-Mathematician-Sophie-Germain-by-Cheryl-Bardoe.pdf
    • http://kiteeearpdf.myhome.cx/3f213f216f213f211f211/Lolly-Learns-a-Lesson-Classroom-Kink-1-by-Cara-Cane.pdf
    • http://kiteeearpdf.myhome.cx/9f210f217f211f211f212/Sophie-s-War-The-Journal-Of-Anna-Sophie-Franziska-Guenther-by-Janice-Shefelman.pdf
    • http://kiteeearpdf.myhome.cx/8f213f212f215f211f218/Sophie-in-the-Saddle-Sophie-4-by-Dick-King-Smith.pdf
    • http://kiteeearpdf.myhome.cx/2f214f214f214f210f210/Sophie-s-Snail-Sophie-1-by-Dick-King-Smith.pdf
    • http://kiteeearpdf.myhome.cx/4f219f217f214f211f213/Never-Give-In-The-Best-of-Winston-Churchill-s-Speeches-by-Winston-S-Churchill.pdf