Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d8b363392fbb077…

MALICIOUS

PDF

17.3 KB Created: 2020-03-20 12:18:10 +00:00 Authoring application: mPDF 5.7
MD5: aa3555ec02e2328191fc4ce9f120b089 SHA-1: 6081ab24749efc6c6c24e638c9d4c35d5bfb75ce SHA-256: 2d8b363392fbb0775db07288e6f7b2ac8a830e46132d3dc0a6b2298393affe27
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. The embedded links, such as http://ieuicufioao.myhome.cx/5550553550559554/A-Hope-Springs-Christmas-Brides-of-Amish-Country-7-by-Patricia-Davids.pdf, likely lead to malicious websites or further download stages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/5550553550559554/A-Hope-Springs-Christmas-Brides-of-Amish-Country-7-by-Patricia-Davids.pdf
    • http://ieuicufioao.myhome.cx/3558558559550559/The-Amish-Nanny-s-Sweetheart-Amish-Country-Brides-2-by-Jan-Drexler.pdf
    • http://ieuicufioao.myhome.cx/3557554556552554/A-Country-Christmas-by-Patricia-Rice.pdf
    • http://ieuicufioao.myhome.cx/2555551555557552/An-Amish-Family-Christmas-Heart-of-Christmas-A-Plain-Holiday-by-Marta-Perry.pdf
    • http://ieuicufioao.myhome.cx/4558552553551553/The-Secret-Wedding-Wish-The-Brides-of-Holly-Springs-2-by-Cathy-Gillen-Thacker.pdf
    • http://ieuicufioao.myhome.cx/1559550559553552/The-Virgin-s-Secret-Marriage-The-Brides-of-Holly-Springs-1-by-Cathy-Gillen-Thacker.pdf
    • http://ieuicufioao.myhome.cx/1553558558559554/When-Hope-Springs-New-Canadian-West-4-by-Janette-Oke.pdf
    • http://ieuicufioao.myhome.cx/1550553552558559553/The-Promise-of-Palm-Grove-Amish-Brides-of-Pinecraft-1-by-Shelley-Shepard-Gray.pdf
    • http://ieuicufioao.myhome.cx/3554558555557552/The-Promise-of-Palm-Grove-Amish-Brides-of-Pinecraft-1-by-Shelley-Shepard-Gray.pdf
    • http://ieuicufioao.myhome.cx/6558558553556556/Echo-Bayou-Springs-Alien-Mail-Order-Brides-3-Intergalactic-Dating-Agency-19-by-Kenzie-Cox.pdf
    • http://ieuicufioao.myhome.cx/4553553559550555/The-Sweetness-of-Honey-Hope-Springs-3-by-Alison-Kent.pdf
    • http://ieuicufioao.myhome.cx/9555550551555554/Forever-Friends-Hope-Springs-3-by-Lynne-Hinton.pdf
    • http://ieuicufioao.myhome.cx/4557556559555556/Beneath-the-Patchwork-Moon-Hope-Springs-2-by-Alison-Kent.pdf
    • http://ieuicufioao.myhome.cx/5550553553552550/A-Blue-and-Gray-Christmas-Christmas-Keeps-Love-and-Hope-Alive-During-War-by-Vickie-McDonough.pdf
    • http://ieuicufioao.myhome.cx/4558551553556554/The-Christmas-Wish-Powder-Springs-2-by-Maggie-Marr.pdf
    • http://ieuicufioao.myhome.cx/2557551557554554/The-Christmas-Light-Christmas-Hope-7-by-Donna-VanLiere.pdf
    • http://ieuicufioao.myhome.cx/2557550551552552/The-Christmas-Blessing-Christmas-Hope-2-by-Donna-VanLiere.pdf
    • http://ieuicufioao.myhome.cx/2552555551553550/The-Christmas-Wishing-Tree-Eternity-Springs-15-by-Emily-March.pdf
    • http://ieuicufioao.myhome.cx/2554553553558558/Bride-of-the-High-Country-Runaway-Brides-3-by-Kaki-Warner.pdf
    • http://ieuicufioao.myhome.cx/3557553556556557/An-Amish-Christmas-Quilt-Seasons-of-the-Heart-4-5-by-Charlotte-Hubbard.pdf
    • http://ieuicufioao.myhome.c