Malicious PDF — malware analysis report

Static analysis result for SHA-256 234395b350e0f2b7…

MALICIOUS

PDF

21.6 KB Created: 2020-03-15 20:32:22 +00:00 Authoring application: mPDF 5.7
MD5: b4dd45c5ede342c4c20b5a01f6037df1 SHA-1: 8d1fbe1768c5041b5fe786e6da06f2f7762b54d2 SHA-256: 234395b350e0f2b7028c89bb979532fd910296d8f0495590b8352abeabb0620c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs likely serve as a lure or a distribution point for further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://peldoaio.myhome.cx/73d43d43d83d53d8/Run-Through-the-Jungle-Real-Adventures-in-Vietnam-with-the-173rd-Airborne-Brigade-by-Larry-J-Musson.pdf
    • http://peldoaio.myhome.cx/13d13d83d63d53d93d7/A-Year-In-Vietnam-With-The-101st-Airborne-1969-1970-by-Harry-G-Enoch.pdf
    • http://peldoaio.myhome.cx/33d33d73d23d03d5/Adventures-in-the-Rifle-Brigade-by-Garth-Ennis.pdf
    • http://peldoaio.myhome.cx/53d03d73d23d73d7/No-Peace-No-Honor-Nixon-Kissinger-and-Betrayal-in-Vietnam-by-Larry-Berman.pdf
    • http://peldoaio.myhome.cx/23d13d03d73d23d2/Kill-Anything-That-Moves-The-Real-American-War-in-Vietnam-by-Nick-Turse.pdf
    • http://peldoaio.myhome.cx/43d23d83d13d83d3/The-Melancholy-of-Suzumiya-Haruhi-chan-The-Untold-Adventures-of-the-SOS-Brigade-Vol-01-by-Nagaru-Tanigawa.pdf
    • http://peldoaio.myhome.cx/93d83d83d23d0/Jungle-Calls-The-Rani-Adventures-3-by-Ron-Snell.pdf
    • http://peldoaio.myhome.cx/93d83d13d13d2/Life-Is-a-Jungle-The-Rani-Adventures-2-by-Ron-Snell.pdf
    • http://peldoaio.myhome.cx/43d63d83d93d43d1/Entwined-The-Erotic-Adventures-of-Jane-in-the-Jungle-1-by-Colette-Gale.pdf
    • http://peldoaio.myhome.cx/13d83d23d83d63d3/Inside-Out-Real-Change-Is-Possible-If-You-re-Willing-to-Start-from-The-by-Larry-Crabb.pdf
    • http://peldoaio.myhome.cx/13d43d03d83d6/The-Land-I-Lost-Adventures-of-a-Boy-in-Vietnam-by-Huynh-Quang-Nhuong.pdf
    • http://peldoaio.myhome.cx/33d63d63d83d33d8/Body-Drama-Real-Girls-Real-Bodies-Real-Issues-Real-Answers-by-Nancy-Amanda-Redd.pdf
    • http://peldoaio.myhome.cx/13d03d33d53d03d83d5/The-Adventures-of-Larry-Lemming-by-Alan-Cartmell.pdf
    • http://peldoaio.myhome.cx/33d43d33d43d93d1/Up-and-Down-Stairs-The-History-of-the-Country-House-Servant-by-Jeremy-Musson.pdf
    • http://peldoaio.myhome.cx/73d73d33d93d93d0/The-Jungle-Book---Le-Livre-De-La-Jungle-A-Bilingual-Reader---Une-Livre-Bilingue-Classical-Language-Skills-Development-Series-8-by-Rudyard-Kipling.pdf
    • http://peldoaio.myhome.cx/63d23d43d13d33d1/The-Jungle-Book-Le-Livre-de-la-jungle-Bilingual-parallel-text---Bilingue-avec-le-texte-parall-le-English---French-Anglais---Fran-ais-Dual-Language-Easy-Reader-45-by-Rudyard-Kipling.pdf
    • http://peldoaio.myhome.cx/53d03d13d43d23d9/Top-Tips-for-Girls-Real-Advice-from-Real-Women-for-Real-Life-by-Kate-Reardon.pdf
    • http://peldoaio.myhome.cx/53d63d73d53d23d8/The-Medium-Next-Door-Adventures-of-a-Real-Life-Ghost-Whisperer-by-Maureen-Hancock.pdf
    • http://peldoaio.myhome.cx/43d23d53d43d43d9/American-Legend-The-Real-Life-Adventures-of-David-Crockett-by-Buddy-Levy.pdf
    • http://peldoaio.myhome.cx/63d03d13d23d93d8/Le-livre-de-la-jungle-suivie-de-Le-second-livre-de-la-jungle-dition-int-grale-by-Rudyard-Kipling.pdf
    • http://peldoaio.myhome.cx/43d23d8