Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c1010272e10bdbd…

MALICIOUS

PDF

20.5 KB Created: 2020-03-12 00:54:43 +00:00 Authoring application: mPDF 5.7
MD5: b43b67a2e30bc0ef8b6648b9ab13d861 SHA-1: be3c3d48d41b8b44a71c5cc3be13cf5b0ae554e1 SHA-256: 3c1010272e10bdbd84cbb41a8e9f6c0847a926d5fb29ebf0670e11367099daca
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO spam or to distribute further malicious content. The ML classifier strongly indicated maliciousness. The embedded URLs point to a domain that appears to be hosting a large collection of book-themed PDFs, suggesting a content-laundering or redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/26a06a26a26a26a0/Charmed-by-Love-The-Brays-3-Love-in-Bloom-83-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a26a26a1/Rocked-by-Love-The-Brays-2-Love-in-Bloom-82-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a96a6/Burning-For-Love-The-Steeles-5-Love-in-Bloom-73-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a86a36a0/Game-of-Love-Love-in-Bloom-10-The-Remingtons-1-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a16a06a0/Tamed-By-Love-The-Steeles-4-Love-in-Bloom-72-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/16a76a16a66a16a3/Flames-of-Love-Love-in-Bloom-12-The-Remingtons-3-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a96a1/Craving-Her-Love-The-Steeles-2-Love-in-Bloom-70-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a36a36a3/Lessons-in-Love-The-Stones-4-Love-in-Bloom-77-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a86a16a96a16a3/Dreaming-of-Love-Love-in-Bloom-19-The-Bradens-11-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a96a9/Eager-for-Love-The-Steeles-1-Love-in-Bloom-69-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a36a2/Flames-of-Love-The-Remingtons-3-Love-in-Bloom-12-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a96a4/Seduced-by-Love-The-Steeles-3-Love-in-Bloom-71-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a46a4/Daring-Her-Love-The-Bradens-Novellas-Collection-The-Bradens-9-Love-in-Bloom-23-1001-Dark-Nights-30-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a46a76a6/Blazing-Summer-2-Love-in-Bloom-79-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a56a5/Crushing-on-Love-The-Bradens-at-Peaceful-Harbor-MD-4-The-Bradens-20-Love-in-Bloom-35-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a46a3/Healed-By-Love-The-Bradens-at-Peaceful-Harbor-1-The-Bradens-13-Love-in-Bloom-32-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a56a7/Whisper-of-Love-The-Bradens-at-Peaceful-Harbor-MD-5-The-Bradens-21-Love-in-Bloom-36-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a56a4/Our-New-Love-The-Bradens-Novellas-Collection-The-Bradens-8-Love-in-Bloom-22-5-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/56a06a06a36a46a2/Sisters-in-Love-Love-in-Bloom-Snow-Sisters-Book-1-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/16a76a16a56a46a9/Romancing-My-Love-The-Bradens-at-Trusty-CO-3-The-Bradens-13-Love-in-Bloom-18-by-Melissa-Foster.pdf
    • http://rtuninnsi.myhome.cx/26a06a26a06a96a9/Eager-for-Love-Th