Malicious PDF — malware analysis report

Static analysis result for SHA-256 315367c901250b90…

MALICIOUS

PDF

23.9 KB Created: 2020-03-15 21:08:37 +00:00 Authoring application: mPDF 5.7
MD5: a5a73e92752d32d1e1238c0075b9f017 SHA-1: f3b9f812fa4bc6ed2a2464a52601b62e83538312 SHA-256: 315367c901250b90f55fec9d9ff43124873e0fe2733d85f4376d550fc67ff9d3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on the same domain, suggesting a link farm or redirection scheme. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/76a16a86a96a0/-Un-like-a-Virgin-by-Lucy-Anne-Holmes.pdf
    • http://rtuninnsi.myhome.cx/96a16a56a16a76a4/Wer-braucht-schon-Schmetterlinge-im-Bauch-Roman-by-Lucy-Anne-Holmes.pdf
    • http://rtuninnsi.myhome.cx/26a46a46a46a96a7/Craving-Lucy-Lucy-amp-Harris-2-by-Terri-Anne-Browning.pdf
    • http://rtuninnsi.myhome.cx/66a96a56a86a26a0/The-Complete-Sherlock-Holmes-The-Adventures-of-Sherlock-Holmes-the-Reminiscences-of-Sherlock-Holmes-the-Return-of-Sherlock-Holmes-the-Memoirs-of-Sherlock-Holmes-the-Casebook-of-Sherlock-Holmes-by-Arthur-Conan-Doyle.pdf
    • http://rtuninnsi.myhome.cx/86a96a96a56a26a4/The-Last-Moriarty-A-Sherlock-Holmes-and-Lucy-James-Mystery-1-by-Charles-Veley.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a96a26a4/The-Greek-s-Innocent-Virgin-Kouros-Brothers-Duo-1-Greek-Tycoons-2-by-Lucy-Monroe.pdf
    • http://rtuninnsi.myhome.cx/36a86a16a96a56a3/Rocking-Kin-Lucy-amp-Harris-3-by-Terri-Anne-Browning.pdf
    • http://rtuninnsi.myhome.cx/86a66a46a16a36a0/Die-Memoiren-des-Sherlock-Holmes-Holmes-erstes-Abenteuer-und-andere-Detektivgeschichten-The-Memoirs-of-Sherlock-Holmes-The-Gloria-Scott-and-Other-Gesicht-und-vieles-mehr-by-Arthur-Conan-Doyle.pdf
    • http://rtuninnsi.myhome.cx/76a76a26a56a56a8/Virgin-Outcast-Bred-to-the-Beast-The-Virgin-Trilogy-1-by-Fannie-Tucker.pdf
    • http://rtuninnsi.myhome.cx/86a26a26a46a66a9/The-Ruthless-Magnate-s-Virgin-Mistress-Virgin-Brides-Arrogant-Husbands-2-by-Lynne-Graham.pdf
    • http://rtuninnsi.myhome.cx/66a86a56a16a26a6/Anne-of-the-Island-by-Lucy-Maud-Montgomery-Unabridged-1915-Original-Version-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/66a66a96a46a16a8/The-Virgin-Revenge-The-Virgin-1-by-J-Dallas.pdf
    • http://rtuninnsi.myhome.cx/76a76a36a96a8/Sherlock-Holmes-and-the-Adventure-of-the-Six-Napoleons-On-the-Case-with-Holmes-amp-Watson-9-by-Murray-Shaw.pdf
    • http://rtuninnsi.myhome.cx/96a76a46a76a36a8/Dear-Mr-Holmes-Seven-Holmes-on-the-Range-Mysteries-by-Steve-Hockensmith.pdf
    • http://rtuninnsi.myhome.cx/86a76a66a96a06a5/Sherlock-Holmes-Holmes-and-the-Ripper-by-Brian-Clemens.pdf
    • http://rtuninnsi.myhome.cx/16a16a86a76a06a76a1/Anne-of-Green-Gables-the-Children-s-Classic-Novel-by-Lucy-Maud-Montgomery-Classic-Books-by-L-M-Montgomery.pdf
    • http://rtuninnsi.myhome.cx/76a06a86a06a36a9/Welkom-in-Virgin-River-Virgin-River-2-by-Robyn-Carr.pdf
    • http://rtuninnsi.myhome.cx/26a96a66a76a06a7/A-Virgin-River-Christmas-Virgin-River-4-by-Robyn-Carr.pdf
    • http://rtuninnsi.myhome.cx/36a16a26a16a96a1/The-Sad-Blue-Frog-by-Jeri-Holmes-J-S-Holmes-.pdf
    • http://rtuninnsi.myhome.cx/26a96a56a16a86a8/The-Lucy-Family-Alphabet-by-Judith-Lucy.pdf
    • http://rtuninnsi.myhome.cx/26a0