Malicious PDF — malware analysis report

Static analysis result for SHA-256 2665f116e9a2bc7b…

MALICIOUS

PDF

16.1 KB Created: 2020-03-18 16:26:01 +00:00 Authoring application: mPDF 5.7
MD5: 7d91cb62eab24940f39b2fcf4b7d7a7e SHA-1: b05374a78671a5914895cd558ac362404b204bdc SHA-256: 2665f116e9a2bc7b96f77232dc1c0cdebe0a14e82262478d1655eebaea056496
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles. This suggests a tactic to lure users through search engine results or to distribute malicious content disguised as legitimate files. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the document. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/36a26a56a56a9/Anne-of-Avonlea-Anne-of-Green-Gables-2-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/26a86a06a16a46a3/Anne-of-Green-Gables-Series-and-Chronicles-of-Avonlea-and-Further-Chronicles-of-Avonlea-Anne-of-Green-Gables-1-6-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/66a66a96a16a36a9/Anne-Tina-Hateup-H-jo-Anne-of-Green-Gables-Sundanese-Edition-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/76a76a76a46a46a7/Anne-des-Pignons-Verts-Anne-of-Green-Gables-French-edition-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/46a36a56a96a46a8/Anne-s-House-of-Dreams-Anne-of-Green-Gables-5-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/66a66a66a46a5/Anne-s-House-of-Dreams-Anne-of-Green-Gables-5-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/16a36a66a56a06a4/Anne-of-Green-Gables-Boxed-Set-Anne-of-Green-Gables-1-3-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/46a66a66a16a9/Anne-of-Ingleside-Anne-of-Green-Gables-6-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/16a16a26a56a06a86a3/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/16a96a16a46a16a0/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/36a16a46a46a26a9/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/16a56a96a46a46a2/Anne-of-the-Island-Anne-of-Green-Gables-3-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/36a76a16a86a76a2/Anne-of-Green-Gables-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/46a76a56a46a66a6/Anne-of-Green-Gables-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/66a26a96a46a3/Anne-of-Green-Gables-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/66a06a36a06a16a7/Anne-of-Green-Gables-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/26a86a56a16a46a1/Anne-of-Green-Gables-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/46a36a46a26a56a3/Anne-of-Green-Gables-Anne-of-Green-Gables-1-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/46a56a06a76a86a7/Anne-of-Green-Gables-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/56a56a46a26a76a3/Anne-of-Green-Gables-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/16a16a26a56a06a86a3/Anne-of-the-Island-Anne-of-Green-Gables-3-