Malicious PDF — malware analysis report

Static analysis result for SHA-256 7df2c922641188c5…

MALICIOUS

PDF

18.5 KB Created: 2019-04-30 02:43:48 +01:00 Authoring application: mPDF 5.7
MD5: d0967b49a7690d37734b3e26bd8f02e7 SHA-1: 488592557584bf02607a9703f7d4d61d977d41a0 SHA-256: 7df2c922641188c59408bc92fed2583c64ee482d7294c9b6e98841ed49bfe42f
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is identified as a malicious PDF dropper by ClamAV and an ML classifier. It contains numerous embedded URLs that point to external PDF files, likely intended to trick the user into downloading and opening further malicious content. The presence of these links suggests an attempt to deliver a second-stage payload, aligning with the behavior of a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-9538674-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9538674-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/64e54e24e84e24e2/Optics-Paralipomena-to-Witelo-amp-Optical-Part-of-Astronomy-by-Johannes-Kepler.pdf
    • http://unieoooq.linkpc.net/64e54e24e64e74e7/Johannes-Kepler-New-Astronomy-by-Johannes-Kepler.pdf
    • http://unieoooq.linkpc.net/64e54e24e64e84e0/A-History-of-Astronomy-from-Thales-to-Kepler-by-J-L-E-Dreyer.pdf
    • http://unieoooq.linkpc.net/64e54e24e64e74e6/The-Six-Cornered-Snowflake-by-Johannes-Kepler.pdf
    • http://unieoooq.linkpc.net/64e54e24e74e34e0/Johannes-Kepler-Life-and-Letters-by-Carola-Baumgardt.pdf
    • http://unieoooq.linkpc.net/64e54e24e64e74e5/Johannes-Kepler-Giant-of-Faith-and-Science-by-John-Hudson-Tiner.pdf
    • http://unieoooq.linkpc.net/64e94e04e04e44e3/Johannes-Martini-And-Johannes-Brebis-Sacred-Music-Part-1-Hymns-Magnificats-Motets-And-Passions-Thirty-Six-Settings-Of-An-Italian-Song-by-Murray-Steib.pdf
    • http://unieoooq.linkpc.net/64e54e24e74e24e9/Kepler-One-The-Choosing-Kepler-One-Series-Book-1-by-T-P-Keane.pdf
    • http://unieoooq.linkpc.net/74e24e14e94e14e3/Pope-John-Paul-IIs-Theological-Journey-to-the-Prayer-Meeting-of-Religions-in-Assisi-Part-2-3-by-Johannes-D-rmann.pdf
    • http://unieoooq.linkpc.net/14e14e04e94e04e04e4/Parerga-and-Paralipomena-Short-Philosophical-Essays-Vol-2-by-Arthur-Schopenhauer.pdf
    • http://unieoooq.linkpc.net/74e84e84e54e04e7/Lasers-and-Non-Linear-Optics-by-B-B-Laud.pdf
    • http://unieoooq.linkpc.net/74e04e34e84e84e3/Optics-in-Computing-by-Roger-A-Lessard.pdf
    • http://unieoooq.linkpc.net/84e74e94e04e24e5/Introduction-to-Modern-Optics-by-Grant-R-Fowles.pdf
    • http://unieoooq.linkpc.net/74e74e64e04e04e9/Solar-Cells-Their-Optics-amp-Metrology-by-S-Chomet.pdf
    • http://unieoooq.linkpc.net/14e14e04e84e84e54e3/Parerga-and-Paralipomena-Short-Philosophical-Essays-Vol-1-Parerga-by-Arthur-Schopenhauer.pdf
    • http://unieoooq.linkpc.net/14e04e84e94e04e64e3/Ahornallee-26-Oder-Epitaph-Fur-Johannes-Bobrowski-by-Johannes-Bobrowski.pdf
    • http://unieoooq.linkpc.net/44e84e54e64e7/Johannes-Cabal-the-Necromancer-Johannes-Cabal-1-by-Jonathan-L-Howard.pdf
    • http://unieoooq.linkpc.net/94e84e24e44e94e2/The-Optical-Unconscious-by-Rosalind-E-Krauss.pdf
    • http://unieoooq.linkpc.net/24e34e24e44e04e7/Vision-and-Certitude-in-the-Age-of-Ockham-Optics-Epistemology-and-the-Foundation-of-Semantics-1250-1345-by-Katherine-H-Tachau.pdf
    • http://unieoooq.linkpc.net/94e84e64e74e94e6/Electronic-and-Optical-Properties-of-Mgo-Zno-and-CDO-by-Andr-Schleife.pdf