Malicious PDF — malware analysis report

Static analysis result for SHA-256 b63e792d5201fa66…

MALICIOUS

PDF

16.9 KB Created: 2019-05-07 04:22:59 +01:00 Authoring application: mPDF 5.7
MD5: 30313229d5f2957f12c12c1dcdcacd99 SHA-1: ea4ad5fad4024abf3560dde0f1a368918307d454 SHA-256: b63e792d5201fa667903d4039fa963ff1eee5c9416b5bca70f1ed31e5b93af3a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains embedded URLs that are disguised as book titles, aiming to trick the user into downloading further malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URLs are the primary indicators of compromise, suggesting a delivery mechanism for further stages of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7465748-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7465748-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/2da1da1da7da2da8/The-Needing-Moore-Series-Trilogy-Searching-for-Moore-Moore-to-Lose-amp-Moore-than-Forever-by-Julie-A-Richman.pdf
    • http://seasasac.lflinkup.com/7da8da8da3da3/Searching-For-Moore-Needing-Moore-1-by-Julie-A-Richman.pdf
    • http://seasasac.lflinkup.com/1da7da0da3da1da6/Moore-to-Lose-Needing-Moore-2-by-Julie-A-Richman.pdf
    • http://seasasac.lflinkup.com/1da4da7da0da8da7/Moore-than-Forever-Needing-Moore-3-by-Julie-A-Richman.pdf
    • http://seasasac.lflinkup.com/1da2da2da5da5da9/Moore-than-a-Feeling-by-Julie-A-Richman.pdf
    • http://seasasac.lflinkup.com/5da5da3da6da4da2/A-Chance-for-Moore-Moore-Romance-1-by-Alex-Miska.pdf
    • http://seasasac.lflinkup.com/5da5da3da7da9da0/The-Moore-the-Merrier-Moore-Romance-2-5-by-Alex-Miska.pdf
    • http://seasasac.lflinkup.com/8da8da4da7da2da6/The-Best-of-C-L-Moore-and-Henry-Kuttner-by-C-L-Moore.pdf
    • http://seasasac.lflinkup.com/4da1da1da4da7da9/Henry-Moore-A-Shelter-Sketchbook-Facsimile-by-Henry-Moore.pdf
    • http://seasasac.lflinkup.com/2da5da2da2da4da7/The-Other-Wes-Moore-One-Name-Two-Fates-by-Wes-Moore.pdf
    • http://seasasac.lflinkup.com/2da9da3da4da3da0/Discovering-Wes-Moore-by-Wes-Moore.pdf
    • http://seasasac.lflinkup.com/3da3da6da2da5da3/Love-on-the-Edge-of-Time-by-Julie-A-Richman.pdf
    • http://seasasac.lflinkup.com/9da0da8da3da7da4/The-Poems-of-Marianne-Moore-by-Marianne-Moore.pdf
    • http://seasasac.lflinkup.com/5da5da5da4da6da9/The-Birth-of-a-Bridge-by-Jessica-Moore-translator-Maylis-de-Kerangal-Jessica-Moore-translator-Maylis-de-Kerangal.pdf
    • http://seasasac.lflinkup.com/1da2da1da0da7da2/Olive-Odyssey-Searching-for-the-Secrets-of-the-Fruit-That-Seduced-the-World-by-Julie-Angus.pdf
    • http://seasasac.lflinkup.com/9da2da7da5/How-to-Be-Alone-If-You-Want-To-and-Even-If-You-Don-t-by-Lane-Moore.pdf
    • http://seasasac.lflinkup.com/2da4da2da2da8da6/Self-Help-by-Lorrie-Moore.pdf
    • http://seasasac.lflinkup.com/3da2da3da9da0/V-for-Vendetta-by-Alan-Moore.pdf
    • http://seasasac.lflinkup.com/5da9da0da3da0/Lucky-Ducklings-by-Eva-Moore.pdf
    • http://seasasac.lflinkup.com/3da0da5da2da8da6/Promethea-by-Alan-Moore.pdf