Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e92d79922cb2746…

MALICIOUS

PDF

21.3 KB Created: 2020-03-18 21:39:29 +00:00 Authoring application: mPDF 5.7
MD5: f0eeed1e62c49264fd7fcce42342a09b SHA-1: e813dd936fc29b65f332608978e6f0ae97d6e5ed SHA-256: 3e92d79922cb2746ad20f90d2cd081d5f22b4b56c61d58b715660edfc56f42f6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links, such as http://rtuninnsi.myhome.cx/26a66a46a06a56a3/The-Mistletoe-Murder-and-Other-Stories-by-P-D-James.pdf, likely lead to malicious content or further distribution points. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/26a66a46a06a56a3/The-Mistletoe-Murder-and-Other-Stories-by-P-D-James.pdf
    • http://rtuninnsi.myhome.cx/36a16a46a36a56a1/Mistletoe-and-Murder-Daisy-Dalrymple-11-by-Carola-Dunn.pdf
    • http://rtuninnsi.myhome.cx/16a96a56a96a96a2/Mistletoe-Murder-A-Lucy-Stone-Mystery-1-by-Leslie-Meier.pdf
    • http://rtuninnsi.myhome.cx/46a76a46a3/Mistletoe-Moonlight-amp-Murder-Ravenwood-Cove-Mystery-3-by-Carolyn-L-Dean.pdf
    • http://rtuninnsi.myhome.cx/36a06a26a86a76a5/Men-Under-the-Mistletoe-by-Angela-James.pdf
    • http://rtuninnsi.myhome.cx/46a26a06a46a36a7/The-Mobile-Mistletoe-Series-Boxed-Set-Stories-1-4-by-Jennifer-Conner.pdf
    • http://rtuninnsi.myhome.cx/26a76a96a96a36a4/The-Love-Pirate-and-the-Bandit-s-Son-Murder-Sin-and-Scandal-in-the-Shadow-of-Jesse-James-by-Laura-James.pdf
    • http://rtuninnsi.myhome.cx/76a56a56a36a86a1/JAMES-LEE-BURKE-BOOKS-AND-ALL-SHORT-STORIES-CHECKLIST-AND-SUMMARIES---INCLUDES-LATEST-DAVE-ROBICHEAUX---JAMES-LEE-BURKE-SHORT-STORIES-AND-STANDALONE-NOVELS-AND-CHECKLIST-BEST-READING-ORDER-Book-56-by-Avid-Reader.pdf
    • http://rtuninnsi.myhome.cx/16a96a06a56a06a9/James-Herriot-s-Dog-Stories-Warm-And-Wonderful-Stories-About-The-Animals-Herriot-Loves-Best-by-James-Herriot.pdf
    • http://rtuninnsi.myhome.cx/96a36a76a46a46a4/The-James-Thurber-Audio-Collection-Fables-and-Selected-Stories-by-James-Thurber-by-James-Thurber.pdf
    • http://rtuninnsi.myhome.cx/16a06a26a36a16a26a0/Murder-By-Gun-5-Shocking-Stories-by-Dashiell-Hammett.pdf
    • http://rtuninnsi.myhome.cx/46a26a96a56a36a4/Murder-at-Christmas-And-Other-Stories-by-Cynthia-Manson.pdf
    • http://rtuninnsi.myhome.cx/36a56a76a26a86a9/Heat-and-Murder-by-Christine-James.pdf
    • http://rtuninnsi.myhome.cx/36a06a26a46a06a5/The-Murder-of-King-Tut-by-James-Patterson.pdf
    • http://rtuninnsi.myhome.cx/26a96a66a46a76a7/The-Murder-Of-King-Tut-by-James-Patterson.pdf
    • http://rtuninnsi.myhome.cx/16a46a26a36a16a8/The-Murder-of-King-Tut-by-James-Patterson.pdf
    • http://rtuninnsi.myhome.cx/56a36a16a46a3/Murder-In-The-Palace-amp-Other-Short-Stories-by-Priya-Bajpai.pdf
    • http://rtuninnsi.myhome.cx/16a96a46a26a36a2/Best-Ghost-Stories-of-M-R-James-by-M-R-James.pdf
    • http://rtuninnsi.myhome.cx/46a36a56a16a16a2/Murder-Sinful-Secrets-2-by-Ella-James.pdf
    • http://rtuninnsi.myhome.cx/26a96a46a26a46a9/The-Crow-s-Murder-Kit-Davenport-5-by-Tate-James.pdf