Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa442bf8333250ec…

MALICIOUS

PDF

18.1 KB Created: 2019-04-30 04:28:25 +01:00 Authoring application: mPDF 5.7
MD5: 13a33b2e6441645a2aa4347aa000e7e3 SHA-1: dcde3e1dcdf971b1f1c24d55ab8491d50460270c SHA-256: fa442bf8333250ecba590de5abf9e0048709c2b2ad801cfaccb43e039948fa74
92 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The file is identified as malicious by ClamAV and an ML classifier, indicating it's a PDF dropper. The document body and heuristics reveal an embedded URL, http://seasasac.lflinkup.com/2da0da6da5da9da8/Skin-Deep-Dark-World-1-by-T-G-Ayer.pdf, which is likely used to download a secondary payload. The presence of numerous similar URLs suggests a pattern of distributing malicious content disguised as book downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7624776-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7624776-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasasac.lflinkup.com/2da0da6da5da9da8/Skin-Deep-Dark-World-1-by-T-G-Ayer.pdf
    • http://seasasac.lflinkup.com/5da2da2da9da2da5/Skin-Deep-A-SkinWalker-Novel-1-A-DarkWorld-Series-by-T-G-Ayer.pdf
    • http://seasasac.lflinkup.com/3da4da1da1da9da6/Pounding-Skin-Skin-Deep-Inc-2-by-L-A-Witt.pdf
    • http://seasasac.lflinkup.com/7da6da6da2da7/Skin-Deep-I-Team-5-5-by-Pamela-Clare.pdf
    • http://seasasac.lflinkup.com/3da4da5da0da1da2/Skin-Deep-Harry-Hendrick-1-by-Gary-Kemble.pdf
    • http://seasasac.lflinkup.com/8da9da7da3da8/Skin-Deep-Laura-Blackstone-1-by-Mark-Del-Franco.pdf
    • http://seasasac.lflinkup.com/1da9da4da2da4/Skin-Deep-Magic-by-Craig-Laurance-Gidney.pdf
    • http://seasasac.lflinkup.com/1da0da1da1da2da5da8/Skin-Deep-Black-Women-amp-White-Women-Write-About-Race-by-Marita-Golden.pdf
    • http://seasasac.lflinkup.com/1da0da8da7da4da8/Deep-Into-Dark-by-Delphine-Jamet.pdf
    • http://seasasac.lflinkup.com/9da1da7da8da7da9/Deep-Dark-by-Brian-Bargmann.pdf
    • http://seasasac.lflinkup.com/3da5da5da3da4da9/Lovely-Dark-and-Deep-by-Justina-Chen.pdf
    • http://seasasac.lflinkup.com/2da4da1da7da2/Deep-Dark-Fears-by-Fran-Krause.pdf
    • http://seasasac.lflinkup.com/3da7da9da4da5da2/The-Young-Skin-Diet-Science-Based-Recipes-and-Treatments-to-Reveal-Your-Best-Skin-Ever-by-Michelle-Lee.pdf
    • http://seasasac.lflinkup.com/2da4da2da7da5da0/Deep-Control-Dark-Dominance-2-by-Annabel-Joseph.pdf
    • http://seasasac.lflinkup.com/1da0da1da2da3da1da4/Bitcoin-amp-Darknet-The-deep-dark-Web-by-Paul-E-Mann.pdf
    • http://seasasac.lflinkup.com/2da2da8da2da9da0/Deep-and-Dark-and-Dangerous-All-the-Lovely-Bad-Ones-by-Mary-Downing-Hahn.pdf
    • http://seasasac.lflinkup.com/7da3da3da0da0/Parallel-Journeys-by-Eleanor-H-Ayer.pdf
    • http://seasasac.lflinkup.com/3da4da9da7da4da5/Under-Their-Skin-Under-Their-Skin-1-by-Margaret-Peterson-Haddix.pdf
    • http://seasasac.lflinkup.com/2da4da7da0da3da0/Deep-Under-Walker-Security-1-Tall-Dark-amp-Deadly-4-by-Lisa-Renee-Jones.pdf
    • http://seasasac.lflinkup.com/8da6da2da1da9da7/Acne-Simple-Proven-Solution-To-Acne-Free-Skin-How-To-Cure-Acne-For-Good-And-Achieve-Lasting-Acne-Freedom-Acne-Cure-Acne-No-More-Acne-Diet-Clear-Skin-Free-Skin-Get-Rid-Of-Acne-Acne-Treatment-by-Donna-Flinn.pdf
    • http://seasasac.lflinkup.com/3da7da9da4da5da2/The-Young-Skin-Diet-Science-Based-Recipes-and-Treatments-to-Reveal-Your