Malicious PDF — malware analysis report

Static analysis result for SHA-256 374eccbee61727f7…

MALICIOUS

PDF

21.4 KB Created: 2020-03-15 21:08:55 +00:00 Authoring application: mPDF 5.7
MD5: 7e104a07f1a3ef50ca8b8953f3f1f5b3 SHA-1: ad44847a4f006a9fb32b0d9cbf714fd88f6db45b SHA-256: 374eccbee61727f78046086f849a304d14e71872546fbb270d22d2ed6465a4fb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier with high confidence as malicious. Static analysis revealed a PDF_SEO_LINK_FARM heuristic firing, indicating the presence of numerous external links within the document. The primary attack pattern observed is the embedding of a large number of URLs, likely to distribute malicious content or engage in SEO abuse. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/26a36a36a46a96a7/Shelter-Me-by-Alex-McAulay.pdf
    • http://rtuninnsi.myhome.cx/86a66a26a06a76a8/Girls-of-July-by-Alex-Flinn.pdf
    • http://rtuninnsi.myhome.cx/86a16a36a86a9/24-Girls-in-7-Days-by-Alex-Bradley.pdf
    • http://rtuninnsi.myhome.cx/46a46a66a46a76a3/The-Girls-with-Games-of-Blood-by-Alex-Bledsoe.pdf
    • http://rtuninnsi.myhome.cx/36a36a36a06a3/Kiss-the-Girls-Alex-Cross-2-by-James-Patterson.pdf
    • http://rtuninnsi.myhome.cx/26a16a66a46a96a4/Girls-Girls-Girls-The-Black-Book-Diary-of-a-Teenage-Stud-1-by-Jonah-Black.pdf
    • http://rtuninnsi.myhome.cx/46a16a96a16a86a4/--LOST-GIRLS-1-Shingeki-no-Kyojin-Lost-Girls-1-Attack-on-Titan-Lost-Girls-Manga-1-by-Hajime-Isayama.pdf
    • http://rtuninnsi.myhome.cx/76a76a06a06a46a1/Articles-on-Juvenile-Series-Including-Tom-Swift-Nancy-Drew-Tom-Swift-Jr-the-Dana-Girls-Goosebumps-Alex-Rider-the-Mad-Scientists-Club-Everworld-Gossip-Girl-Bobbsey-Twins-Danny-Dunn-Remnants-Rover-Boys-Three-Investigators-by-Hephaestus-Books.pdf
    • http://rtuninnsi.myhome.cx/36a26a46a86a16a9/Alex-in-Rome-Alex-Archer-3-by-Tessa-Duder.pdf
    • http://rtuninnsi.myhome.cx/26a46a96a66a16a1/Glitter-Girls-and-the-Great-Fake-Out-Allie-Finkle-s-Rules-for-Girls-5-by-Meg-Cabot.pdf
    • http://rtuninnsi.myhome.cx/36a16a36a46a06a3/Glitter-Girls-and-the-Great-Fake-Out-Allie-Finkle-s-Rules-for-Girls-5-by-Meg-Cabot.pdf
    • http://rtuninnsi.myhome.cx/26a36a26a06a26a9/Ask-a-Queer-Chick-A-Guide-to-Sex-Love-and-Life-for-Girls-Who-Dig-Girls-by-Lindsay-King-Miller.pdf
    • http://rtuninnsi.myhome.cx/36a76a86a06a76a8/Girls-Will-Be-Girls-A-Novella-and-Short-Stories-by-Lesl-a-Newman.pdf
    • http://rtuninnsi.myhome.cx/66a56a26a76a86a4/Squirting-Girls-Pretty-And-Horny-Squirty-Girls-Show-How-Wet-They-Are-Adult-Picture-Books-by-Romae-Brady.pdf
    • http://rtuninnsi.myhome.cx/46a26a46a06a96a7/The-Girls-In-the-Back-of-the-Class-They-re-High-School-Girls-With-Secrets-Trouble-And-Two-Choices-Dropping-Out-Or-Trusting-Her-by-LouAnne-Johnson.pdf
    • http://rtuninnsi.myhome.cx/16a36a56a46a96a8/Gossip-Girls-the-Girls-Club-by-Dionne-L-Fields.pdf
    • http://rtuninnsi.myhome.cx/36a56a46a56a76a2/Where-Bad-Girls-Go-to-Fall-Good-Girls-2-by-Holly-Renee.pdf
    • http://rtuninnsi.myhome.cx/56a36a66a26a66a7/Alex-et-la-magie-des-nombres-by-Alex-Bellos.pdf
    • http://rtuninnsi.myhome.cx/16a56a16a96a36a9/Lightkeepers-Girls-Box-Set-Ten-Girls-by-Irene-Howat.pdf
    • http://rtuninnsi.myhome.cx/76a46a06a96a8/Big-Girls-Do-It-Married-Big-Girls-Do-It-5-by-Jasinda-Wilder.pdf