Malicious PDF — malware analysis report

Static analysis result for SHA-256 a63a3f0339e16f0e…

MALICIOUS

PDF

23.9 KB Created: 2020-03-18 22:40:56 +00:00 Authoring application: mPDF 5.7
MD5: 8ce06f5dad985cff3fdfa38d9ebc01e0 SHA-1: bf60ad8a277575e588775504d20e22da510f02a4 SHA-256: a63a3f0339e16f0ed51f5d95eef2275cb5d6323dbe57457e9029e19f62fbc323
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was detected as a dropper by ClamAV. It contains multiple embedded URLs that redirect to external resources. The primary attack pattern involves luring the user to click these links, which likely leads to the download and execution of a secondary payload. The document body was not sufficiently readable to determine a specific lure, but the presence of numerous links suggests a broad phishing or malware distribution attempt.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7678077-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7678077-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ewasocmo.myhome.cx/3c34c38c38c38c39/Fuel-to-the-Fire-Fuel-to-the-Fire-1-by-David-Staniforth.pdf
    • http://ewasocmo.myhome.cx/3c34c39c30c38c33/Ruler-s-Desire-Fuel-to-the-Fire-2-by-David-Staniforth.pdf
    • http://ewasocmo.myhome.cx/4c30c39c35c30c31/Fuel-for-Fire-Black-Knights-Inc-10-by-Julie-Ann-Walker.pdf
    • http://ewasocmo.myhome.cx/4c37c34c36c32/The-Last-Dragon-Chronicles-Complete-Set-Books-1-5-The-Fire-Within-Icefire-Fire-Star-The-Fire-Eternal-and-Dark-Fire-5-Book-Set-by-Chris-d-39-Lacey.pdf
    • http://ewasocmo.myhome.cx/4c34c36c36c36c39/Fire-Underground-The-Ongoing-Tragedy-of-the-Centralia-Mine-Fire-by-David-DeKok.pdf
    • http://ewasocmo.myhome.cx/3c37c39c31c35c34/That-Night-Filled-Mountain-by-Skitz-O-39-Fuel.pdf
    • http://ewasocmo.myhome.cx/1c39c33c36c31c35/Jean-Grey-Vol-1-Nightmare-Fuel-by-Dennis-Hopeless.pdf
    • http://ewasocmo.myhome.cx/1c30c38c33c35c35c38/TurboCharged-Recipes-Delicious-Fuel-for-Your-Fabulous-Fat-Burning-Machine-by-Tom-Griesel.pdf
    • http://ewasocmo.myhome.cx/7c31c35c31c30c31/Benchmarking-Workstations-With-The-Fast-Reactor-Fuel-Performance-Code-Trafic-by-R-Thetford.pdf
    • http://ewasocmo.myhome.cx/5c30c37c33c36c30/The-Jew-is-Not-My-Enemy-Unveiling-the-Myths-That-Fuel-Muslim-Anti-Semitism-by-Tarek-Fatah.pdf
    • http://ewasocmo.myhome.cx/1c30c38c33c35c32c31/Turbocharged-Recipes-Delicious-Fuel-for-Your-Fabulous-Fat-Burning-Machine-by-Dian-Griesel.pdf
    • http://ewasocmo.myhome.cx/3c34c31c35c34c37/The-Carbon-Free-Home-36-Remodeling-Projects-to-Help-Kick-the-Fossil-Fuel-Habit-by-Stephen-Hren.pdf
    • http://ewasocmo.myhome.cx/4c39c37c34c30c36/The-Happiness-Advantage-The-Seven-Principles-of-Positive-Psychology-That-Fuel-Success-and-Performance-at-Work-by-Shawn-Achor.pdf
    • http://ewasocmo.myhome.cx/9c34c37c32c31c37/Magnitude-and-Distribution-of-Fuel-Subsidies-Evidence-from-Bolivia-Ghana-Jordan-Mali-and-Sri-Lanka-by-Kangni-Kpodar.pdf
    • http://ewasocmo.myhome.cx/3c31c37c30c32c38/Young-Men-and-Fire-A-True-Story-of-the-Mann-Gulch-Fire-by-Norman-Maclean.pdf
    • http://ewasocmo.myhome.cx/5c31c39c30c39c34/Fire-in-America-A-Cultural-History-of-Wildland-and-Rural-Fire-by-Stephen-J-Pyne.pdf
    • http://ewasocmo.myhome.cx/4c32c33c36c31c36/Fire-with-Fire-New-Female-Power-and-How-It-Will-Change-the-Twenty-First-Century-by-Naomi-Wolf.pdf
    • http://ewasocmo.myhome.cx/2c38c31c35c32c35/Playing-with-Fire-Sweet-Pepper-Fire-Brigade-Mystery-2-by-J-J-Cook.pdf
    • http://ewasocmo.myhome.cx/2c37c33c36c39/Fire-with-Fire-Tales-of-the-Terran-Republic-1-by-Charles-E-Gannon.pdf
    • http://ewasocmo.myhome.cx/9c35c38c39c35c35/Through-the-Fire-Based-on-a-True-Story-About-a-Young-Girl-That-Was-Maliciously-Burned-in-a-House-Fire-by-Theresa-A-Vandermeer.pdf
    • http://ewasocmo.myhome.cx/1c30c38c33c35c35c38/TurboCharged-Recipes-Delicious-Fuel-for-Your-Fabu