Malicious PDF — malware analysis report

Static analysis result for SHA-256 33532cfedf6b7200…

MALICIOUS

PDF

19.2 KB Created: 2020-03-15 09:46:37 +00:00 Authoring application: mPDF 5.7
MD5: 8348ffa9105b8d799751e541e072c36b SHA-1: 96dd4766b49ac4228d74067c744686cdea9b558d SHA-256: 33532cfedf6b72004d788195046361df1773e91bf54e7bdf96b270ce4992412f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm, suggesting a SEO spam or phishing campaign. The ML classifier strongly supports the malicious verdict. No scripts were extracted, but the sheer volume of outbound links points to a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/13d03d13d53d63d33d8/Frauenfedern-morden-sanfter-Band-2---Zwei-Kriminalromane-by-Karin-Welters.pdf
    • http://tanceubio.myhome.cx/73d13d63d43d43d9/Heimlich-geliebt-Zwei-Seiten-einer-Medaille-by-Karin-Kaiser.pdf
    • http://tanceubio.myhome.cx/83d93d83d03d53d3/Dunkle-Machenschaften-Kurzkrimis-Band-1-by-Karin-Denzer.pdf
    • http://tanceubio.myhome.cx/13d13d93d73d53d93d9/Bernsteingrab-amp-Der-Irrl-ufer-Zwei-Thriller-in-einem-Band-by-Andreas-G-ling.pdf
    • http://tanceubio.myhome.cx/13d03d13d53d93d03d6/Wunderbare-Alltagsr-tsel-Zwei-Bestseller-in-einem-Band-by-Mick-O-39-Hare.pdf
    • http://tanceubio.myhome.cx/13d03d53d53d53d13d7/Venezianische-Scharade-Vendetta-Zwei-Romane-in-einem-Band-by-Donna-Leon.pdf
    • http://tanceubio.myhome.cx/83d83d63d33d83d8/So-finster-dein-Herz-Zwei-Thriller-in-einem-Band-by-Daniela-Arnold.pdf
    • http://tanceubio.myhome.cx/93d43d93d13d23d0/Feuermale-Dunkle-Pfade-Zwei-Romane-In-Einem-Band-by-Tami-Hoag.pdf
    • http://tanceubio.myhome.cx/13d03d73d33d73d93d0/Die-Braut-des-Herzogs-Maskerade-in-Rampstade-Zwei-Romane-in-einem-Band-by-Sophia-Farago.pdf
    • http://tanceubio.myhome.cx/13d03d93d33d63d13d8/Eiskalte-Umarmung-amp-Eiskalter-Schlaf-Zwei-Romane-in-einem-Band-by-Astrid-Korten.pdf
    • http://tanceubio.myhome.cx/93d23d03d63d53d3/Insel-Der-Nackten-Frauen-Die-Skrupellose-Zwei-Romane-In-Einem-Band-by-Inger-Frimansson.pdf
    • http://tanceubio.myhome.cx/13d03d63d53d73d33d0/Vertrauter-Fremder-Nachricht-aus-der-Ferne-Zwei-Romane-in-einem-Band-by-Danielle-Steel.pdf
    • http://tanceubio.myhome.cx/93d73d43d83d23d1/Der-wandernde-Wald-Die-brennende-Stadt-Zwei-Romane-in-einem-Band-by-Wolfgang-Hohlbein.pdf
    • http://tanceubio.myhome.cx/83d83d63d33d93d4/H-ter-der-Worte-amp-So-finster-so-kalt-Zwei-Romane-in-einem-Band-by-Diana-Menschig.pdf
    • http://tanceubio.myhome.cx/83d93d43d43d33d9/Der-Hypnotiseur-Paganinis-Fluch-Zwei-Joona-Linna-Romane-in-einem-Band-by-Lars-Kepler.pdf
    • http://tanceubio.myhome.cx/13d03d53d93d03d13d3/Im-Bruchteil-der-Sekunde-Mit-jedem-Schlag-der-Stunde-Zwei-Thriller-in-einem-Band-Roman-by-David-Baldacci.pdf
    • http://tanceubio.myhome.cx/13d13d63d53d93d93d9/Bridget-Jones-Schokolade-zum-Fr-hst-ck-Am-Rande-des-Wahnsinns-Zwei-Romane-in-einem-Band-by-Helen-Fielding.pdf
    • http://tanceubio.myhome.cx/83d93d33d03d03d1/Die-K-nige-Kampf-der-K-nige-Zwei-Romane-in-einem-Band-by-Michael-Peinkofer.pdf
    • http://tanceubio.myhome.cx/13d13d03d03d83d83d3/Theodor-K-rners-S-mtliche-Werke-in-zwei-B-nden-Erster-Band-by-Theodor-K-rner.pdf
    • http://tanceubio.myhome.cx/93d93d93d43d03d4/Liebe-ist-kein-Spiel-Wer-von-Liebe-tr-umt-Zwei-Romane-in-einem-Band-by-Marion-Chesney.pdf