Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae3f3b6dd961f48c…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 01:59:24 +01:00 Authoring application: mPDF 5.7
MD5: dc75fa031c5149030ab5828debc0d3db SHA-1: 24d99a5977687c864f7bb8415c757e2b62f47ea3 SHA-256: ae3f3b6dd961f48c60833aa2fd6030e372b31c23442db2a921cf39d3845c4e79
92 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link T1566.002 Spearphishing Attachment

The file is identified as a malicious PDF by both a machine learning classifier and ClamAV, indicating it's a dropper. The document body contains numerous URLs that appear to be lures, disguised as book titles, which likely lead to the download of a second-stage payload. The presence of external URIs and the ClamAV detection strongly suggest a dropper functionality.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7131237-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7131237-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/6da0da0da4da4/Friends-with-Explicit-Benefits-Boxed-Set-Friends-with-Benefits-1-4-by-Luke-Young.pdf
    • http://seasasac.lflinkup.com/4da1da1da4da2da2/Friends-Wanting-Benefits-Friends-with-Benefits-0-5-by-Luke-Young.pdf
    • http://seasasac.lflinkup.com/2da9da3da6da4da3/Friends-With-Multiple-Benefits-Friends-with-Benefits-6-by-Luke-Young.pdf
    • http://seasasac.lflinkup.com/1da0da6da5da4da3da0/Friends-with-Benefits-by-Amy-Brent.pdf
    • http://seasasac.lflinkup.com/4da1da3da0da4da7/Best-Friends-with-Benefits-Most-Likely-To-1-by-Candy-Sloane.pdf
    • http://seasasac.lflinkup.com/1da9da7da6da6da9/Just-Friends-With-Benefits-by-Meredith-Schorr.pdf
    • http://seasasac.lflinkup.com/2da8da6da5da8da1/Friends-with-Benefits-by-Stone-Richards.pdf
    • http://seasasac.lflinkup.com/4da4da0da2da5da9/Friends-with-Benefits-Girl-Next-Door-1-by-C-C-Wood.pdf
    • http://seasasac.lflinkup.com/7da7da7da4da7da8/Friends-With-Benefits-The-Edge-Series-by-Jennifer-Labelle.pdf
    • http://seasasac.lflinkup.com/4da3da2da2da3da1/Friends-With-Benefits-Shifter-Hardball-1-by-Cheyenne-Meadows.pdf
    • http://seasasac.lflinkup.com/8da3da0da9da4/Friends-Without-Benefits-Knitting-in-the-City-2-by-Penny-Reid.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da0da9/Stepbrother-With-Benefits-11-Stepbrother-with-Benefits---Second-Season-5-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da2da4/Stepbrother-With-Benefits-18-Stepbrother-with-Benefits-Third-Season-6-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da0da3/Stepbrother-With-Benefits-7-Stepbrother-with-Benefits-Second-Season-1-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/2da8da6da5da1da8/Enemies-with-Benefits-Enemies-with-Benefits-0-5-by-Annika-Martin.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da1da6/Stepbrother-With-Benefits-14-Stepbrother-with-Benefits-Third-Season-2-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da0da6/Stepbrother-With-Benefits-10-Stepbrother-with-Benefits---Second-Season-4-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da2da1/Stepbrother-With-Benefits-16-Stepbrother-with-Benefits-Third-Season-4-by-Mia-Clark.pdf
    • http://seasasac.lflinkup.com/3da8da0da5da9da2/Jessica-Darling-s-It-List-2-The-Totally-Not-Guaranteed-Guide-to-Friends-Foes-amp-Faux-Friends-by-Megan-McCafferty.pdf
    • http://seasasac.lflinkup.com/2da7da0da5da2da3/Friends-Don-t-Let-Friends-be-Undead-by-Seth-Tucker.pdf
    • http://seasasac.lflinkup.com/1da8da3da6da0da9/Stepbrother-With-Benefits-11-Stepbrother-with-Benefits---Second-Season-5-by-Mia-C