Malicious PDF — malware analysis report

Static analysis result for SHA-256 22d79504e8cc67f1…

MALICIOUS

PDF

21.8 KB Created: 2020-03-19 03:52:32 +00:00 Authoring application: mPDF 5.7
MD5: 9c57e50d407b5ae6864ddb4d5a865703 SHA-1: 4601444fbaa1e52741af75b729459bc49f4f06ab SHA-256: 22d79504e8cc67f1453d102ee52733699c3ba0df25aba650943ca41973bb954f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The document body confirms the presence of these numerous URLs, suggesting a link farm or redirection scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://owlaokopdf.myhome.cx/881648169816081698160/Frankenstein-Mary-Shelley-The-Modern-Prometheus-Frankenstein-s-Monster-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681668163816581638164/The-Essential-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681648168816581608163/The-Story-of-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681618160816081618163/Frankenstein-Galvanised-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581678161816681638163/Frankenstein-o-el-moderno-Prometeo-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581648162816481608160/Frankenstein-or-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/781618161816381688164/Frankenstein-narrated-by-Dan-Stevens-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688161816181628166/Frankenstein-Or-the-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681628164816281608162/Frankenstein-o-el-nuevo-Prometeo-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688165816781688160/Frankenstein-The-Original-1818-Text-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681678165816881608164/Frankenstein-Dracula-Dr-Jekyll-And-Mr-Hyde-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/581668167816881638167/Frankenstein---playscript-adapted-by-Philip-Pullman-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/881638169816681618161/Robert-Andrew-Parker-s-Illustrated-Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/781658169816781648163/Frankenstein-or-The-Modern-Prometheus-The-1818-Text-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681658161816381658165/Frankenstein-Or-the-Modern-Prometheus-1823-Revolution-amp-Romanticism-1789-1834-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/881608167816381648161/Frankenstein-Gothic-Classic---The-Uncensored-1818-Edition-Science-Fiction-Classic-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/681618164816881688168/The-Life-and-Letters-of-Mary-Wollstonecraft-Shelley-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/481658161816281668160/The-Mortal-Immortal-The-Complete-Supernatural-Short-Fiction-of-Mary-Shelley-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/481658160816481658167/Mary-and-Maria-by-Mary-Wollstonecraft-amp-Matilda-by-Mary-Shelley-by-Mary-Wollstonecraft.pdf
    • http://owlaokopdf.myhome.cx/781638161816981648160/Frankenstein-or-The-Modern-Prometheus-Companion-Includes-Study-Guide-Complete-Unabridged-Book-Historical-Context-Biography-Character-Index-and-Unabridged-Book-Annotated-by-Mary-Wollstonecraft-Shelley.pdf
    • http://owlaokopdf.myhome.cx/281688165816781688160/Frankenstein-The-O