Malicious PDF — malware analysis report

Static analysis result for SHA-256 37d548dc18d3e9bd…

MALICIOUS

PDF

23.6 KB Created: 2020-03-18 21:53:32 +00:00 Authoring application: mPDF 5.7
MD5: d40991c3b9170242862fc6ac733c64b5 SHA-1: 2b0e9ee7f7c2d34065469ab243682567794c018d SHA-256: 37d548dc18d3e9bd0ffb98222c14623134064e5fc741ec62a333ea84437b10f3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. The primary attack pattern appears to be SEO spam or redirection to potentially malicious content hosted on the domain peldoaio.myhome.cx.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://peldoaio.myhome.cx/33d93d93d03d43d1/Under-the-Lights-Scoundrels-Short-Stories-2-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/43d53d93d73d13d7/Do-Over-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/33d03d13d13d03d9/Everything-Nice-What-Women-Want-2-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/83d33d03d63d93d2/No-Regrets-June-Girls-2-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/83d73d63d13d5/Come-Monday-Wild-Irish-1-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/13d13d33d13d13d73d6/Outback-Lovers-Foreign-Affairs-4-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/23d13d93d93d33d9/Winter-s-Thaw-Compass-Girls-1-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/23d53d33d13d83d1/Happy-Hour-Love-Lessons-1-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/13d23d03d93d53d4/Friday-I-m-in-Love-Wild-Irish-5-by-Mari-Carr.pdf
    • http://peldoaio.myhome.cx/53d43d43d13d33d5/Babylon-Revisited-and-Other-Stories-Fitzgerald-s-Greatest-Short-Stories-A-Collection-of-short-stories-from-the-author-of-The-Great-Gatsby-The-Side-Button-and-many-other-notable-works-by-F-Scott-Fitzgerald.pdf
    • http://peldoaio.myhome.cx/33d13d33d03d23d7/Short-Stories-for-Girls-and-Young-Women-4-Collection-Includes-an-Assortment-of-15-Short-Stories-Kids-Storybooks-Series-Diaries-Space-Halloween-Adventure-Science-by-Betty-J-Byers.pdf
    • http://peldoaio.myhome.cx/23d83d53d83d93d1/Lord-of-Scoundrels-Scoundrels-3-by-Loretta-Chase.pdf
    • http://peldoaio.myhome.cx/13d13d13d93d1/Lord-of-Scoundrels-Scoundrels-3-by-Loretta-Chase.pdf
    • http://peldoaio.myhome.cx/33d33d53d03d63d6/Lord-of-Scoundrels-Scoundrels-3-by-Loretta-Chase.pdf
    • http://peldoaio.myhome.cx/13d93d43d23d93d1/Articles-on-Short-Stories-by-Ernest-Hemingway-Including-The-Snows-of-Kilimanjaro-Hills-Like-White-Elephants-the-Killers-Short-Story-the-Short-Happy-Life-of-Francis-Macomber-Soldier-s-Home-a-Clean-Well-Lighted-Place-a-Day-s-Wait-by-Hephaestus-Books.pdf
    • http://peldoaio.myhome.cx/13d03d73d83d63d43d2/Electricity-in-the-Aschaffenburger-Hof-Lift-short-short-stories-1-by-Jutta-Mahlke.pdf
    • http://peldoaio.myhome.cx/33d13d33d23d93d1/Short-Stories-For-Early-Reading-Includes-16-Original-Stories-with-Covers-Elementary-Kids-Stories-Childrens-Book-Bundle-Animals-Character-Building-Lessons-by-Betty-J-Byers.pdf
    • http://peldoaio.myhome.cx/33d23d93d13d13d2/Short-And-Simple-A-Collection-of-Short-Stories-by-R-L-Jones.pdf
    • http://peldoaio.myhome.cx/33d83d73d63d03d9/The-Lights-Went-Out-and-Other-Stories-by-Fiona-Cooke-Hogan.pdf
    • http://peldoaio.myhome.cx/73d73d13d33d53d8/Housewife-s-Secrets-and-Other-Erotic-Stories-Six-Slut-Wives-and-Rough-Sex-Erotic-Short-Stories-by-Erotique-Stories.pdf