Malicious PDF — malware analysis report

Static analysis result for SHA-256 0013b2e27852c1ad…

MALICIOUS

PDF

20.8 KB Created: 2020-03-16 18:24:51 +00:00 Authoring application: mPDF 5.7
MD5: 4fed1c5cc6c4c2f8c43b966ad72ac4bf SHA-1: 8a4cfe0dbf9a1bf7cdb30b300c0e436c2b78d644 SHA-256: 0013b2e27852c1adfa8e495bfa392335c66d086e851fdb0fe8e87cbcec86dc32
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs are likely used to redirect users to malicious content or for SEO manipulation, and the document body confirms the presence of these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/33d53d13d63d83d6/All-My-Grandmothers-Could-Sing-Poems-by-Nebraska-Women-by-Judith-Sornberger.pdf
    • http://tanceubio.myhome.cx/53d13d33d73d83d1/Event-Poems-by-Judith-Bishop.pdf
    • http://tanceubio.myhome.cx/13d93d23d53d33d5/Old-English-Poems-Including-Beowulf-Battle-of-Brunanburh-Solomon-and-Saturn-Dream-of-the-Rood-Judith-Poem-Deor-Crist-Widsith-Finnesburg-Fragment-Wulf-and-Eadwacer-the-Wanderer-Poem-the-Seafarer-Poem-the-Wife-s-Lament-Rune-Poems-by-Hephaestus-Books.pdf
    • http://tanceubio.myhome.cx/93d93d03d43d73d5/Women-in-Purple-Rulers-of-Medieval-Byzantium-by-Judith-Herrin.pdf
    • http://tanceubio.myhome.cx/23d73d03d33d93d9/Twisted-Vine-An-Anthology-of-Short-Stories-and-Poems-by-Judith-Victoria-Douglas.pdf
    • http://tanceubio.myhome.cx/83d53d63d23d43d7/Prostitution-and-Victorian-Society-Women-Class-and-the-State-by-Judith-R-Walkowitz.pdf
    • http://tanceubio.myhome.cx/33d83d93d13d43d5/Christmas-Stitches-A-Historical-Romance-Collection-3-Stories-of-Women-Sewing-Hope-and-Love-Through-the-Holidays-by-Judith-McCoy-Miller.pdf
    • http://tanceubio.myhome.cx/43d93d83d93d83d2/Men-and-Women-and-Other-Poems-by-Robert-Browning.pdf
    • http://tanceubio.myhome.cx/23d73d13d43d73d6/The-Grandmothers-by-Doris-Lessing.pdf
    • http://tanceubio.myhome.cx/13d93d33d13d13d9/Lita-Poems-on-Women-by-Ronald-V-Verzo.pdf
    • http://tanceubio.myhome.cx/13d43d33d73d13d3/The-Grandmothers-Four-Short-Novels-by-Doris-Lessing.pdf
    • http://tanceubio.myhome.cx/43d53d93d53d73d6/Reaching-the-Stars-Poems-about-Extraordinary-Women-amp-Girls-by-Jan-Dean.pdf
    • http://tanceubio.myhome.cx/53d13d93d43d23d8/Hidden-Lives-My-Three-Grandmothers-by-Carole-Garibaldi-Rogers.pdf
    • http://tanceubio.myhome.cx/53d13d43d63d53d3/Three-Women-A-Poetic-Triptych-and-Selected-Poems-by-Emma-Eden-Ramos.pdf
    • http://tanceubio.myhome.cx/33d83d63d93d93d2/Grandmothers-of-The-Light-A-Medicine-Woman-s-Sourcebook-by-Paula-Gunn-Allen.pdf
    • http://tanceubio.myhome.cx/13d03d53d33d43d73d0/Parodie-Und-Eigenstaendigkeit-in-Nestroys--Judith-Und-Holofernes--Ein-Vergleich-Mit-Hebbels--Judith--by-Ulrich-Scheck.pdf
    • http://tanceubio.myhome.cx/13d13d33d13d33d9/Our-Grandmothers-Drums-A-Portrait-of-Rural-African-Life-and-Culture-by-Mark-Hudson.pdf
    • http://tanceubio.myhome.cx/13d13d33d83d43d33d7/Nebraska-by-George-Whitmore.pdf
    • http://tanceubio.myhome.cx/23d83d13d13d6/Goodnight-Nebraska-by-Tom-McNeal.pdf
    • http://tanceubio.myhome.cx/33d63d33d63d43d1/A-Bride-for-Tom-Nebraska-Historicals-2-by-Ruth-Ann-Nordin.pdf