Malicious PDF — malware analysis report

Static analysis result for SHA-256 34be1255d3404eac…

MALICIOUS

PDF

21.0 KB Created: 2020-03-18 21:46:21 +00:00 Authoring application: mPDF 5.7
MD5: d9a03a7bd9917ea0707da01fac822a96 SHA-1: c54745e80dc958869925c91c7d8514cde42bb0bf SHA-256: 34be1255d3404eace15dc7b98dcbca3788912fa45a5d87f74814bc762914f779
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this as malicious with high confidence. The URLs point to a domain that appears to be used for hosting these linked documents, suggesting a link farm or redirection scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/46a16a66a46a06a4/Wildwood-Creek-Moses-Lake-4-by-Lisa-Wingate.pdf
    • http://rtuninnsi.myhome.cx/66a86a96a8/Before-We-Were-Yours-by-Lisa-Wingate.pdf
    • http://rtuninnsi.myhome.cx/96a26a06a86a46a6/Die-H-terin-der-Geschichten-by-Lisa-Wingate.pdf
    • http://rtuninnsi.myhome.cx/46a36a46a96a7/Under-Wildwood-Wildwood-Chronicles-2-by-Colin-Meloy.pdf
    • http://rtuninnsi.myhome.cx/26a96a96a66a96a1/Omega-Shadow-Pine-Creek-Lake-Den-3-by-Quinn-Michaels.pdf
    • http://rtuninnsi.myhome.cx/16a06a46a36a46a16a4/Mystery-of-the-Long-Lost-8th-9th-and-10th-Books-of-Moses-Together-with-the-Legend-That-Was-of-Moses-and-44-Keys-to-Universal-Power-by-Henri-Gamache.pdf
    • http://rtuninnsi.myhome.cx/66a06a46a16a06a2/Tending-Roses-Tending-Roses-1-by-Lisa-Wingate.pdf
    • http://rtuninnsi.myhome.cx/66a46a56a56a96a0/Little-House-in-the-Big-Woods-Little-House-on-the-Prairie-Farmer-Boy-On-The-Banks-of-Plum-Creek-By-the-Shores-of-Silver-Lake-The-Long-Winter-Little-Town-on-the-Prairie-These-Happy-Golden-Years-The-First-Four-Years-Little-House-Books-by-Laura-Ingalls-Wilder.pdf
    • http://rtuninnsi.myhome.cx/66a76a76a36a16a9/Return-to-Elm-Creek-More-Quilt-Projects-Inspired-by-the-Elm-Creek-Quilts-Novels-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/46a86a96a76a86a3/Drowning-by-Susan-Wingate.pdf
    • http://rtuninnsi.myhome.cx/36a96a36a96a86a9/Wildwood-by-Drusilla-Campbell.pdf
    • http://rtuninnsi.myhome.cx/16a06a46a06a16a56a1/Wildwood-by-John-Farris.pdf
    • http://rtuninnsi.myhome.cx/36a76a36a96a96a4/Christmas-on-Main-Street-Snowberry-Creek-1-5-Shelter-Bay-6-5-Cricket-Creek-5-5-Bayberry-Island-0-5-by-JoAnn-Ross.pdf
    • http://rtuninnsi.myhome.cx/56a06a96a66a1/Wifeshopping-Stories-by-Steven-Wingate.pdf
    • http://rtuninnsi.myhome.cx/16a06a86a66a66a3/The-Deer-Effect-by-Susan-Wingate.pdf
    • http://rtuninnsi.myhome.cx/16a06a96a06a76a9/Age-of-Shadows-WinGate-Chronicles-1-by-R-A-Foster.pdf
    • http://rtuninnsi.myhome.cx/16a06a46a06a16a56a7/The-Wildwood-Sisters-by-Mandy-Magro.pdf
    • http://rtuninnsi.myhome.cx/46a06a86a06a76a7/The-Lake-Regions-of-Central-Africa-Volume-I-from-Zanzibar-to-Lake-Tanganyika-by-Richard-Francis-Burton.pdf
    • http://rtuninnsi.myhome.cx/56a16a96a46a9/Beneath-the-Lake-Lake-Lanier-Mysteries-1-by-Casi-McLean.pdf
    • http://rtuninnsi.myhome.cx/16a06a66a66a76a2/Beneath-the-Lake-Lake-Lanier-Mysteries-1-by-Casi-McLean.pdf
    • http://rtuninnsi.myhome.cx/66