Malicious PDF — malware analysis report

Static analysis result for SHA-256 512bc6f78d951596…

MALICIOUS

PDF

18.7 KB Created: 2020-03-16 18:24:56 +00:00 Authoring application: mPDF 5.7
MD5: 429866df9c37ea60339895999481118f SHA-1: 8b6d762f3583997da1da2c2d15e9155f44da69b3 SHA-256: 512bc6f78d9515967c9b9065471b250980206a246f061b5de9fdb0fc38aa6d31
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a large number of embedded external links, a technique often used for SEO poisoning or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness. No scripts were extracted, but the PDF structure itself suggests a malicious intent to drive traffic to external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/33d73d43d53d83d3/Mistletoe-And-Magic-Appleton-Sisters-3-by-Katie-Rose.pdf
    • http://tanceubio.myhome.cx/63d43d93d93d33d0/Magic-amp-Mistletoe-by-Annabelle-Jacobs.pdf
    • http://tanceubio.myhome.cx/23d93d93d33d33d5/Shadow-Magic-Sisters-of-Magic-1-by-Donna-Grant.pdf
    • http://tanceubio.myhome.cx/33d73d43d33d03d7/Christmas-Betrothals-Mistletoe-Magic-The-Winter-Queen-by-Sophia-James.pdf
    • http://tanceubio.myhome.cx/53d43d53d13d53d4/Blood-Sisters-Katie-Maguire-5-by-Graham-Masterton.pdf
    • http://tanceubio.myhome.cx/33d93d23d83d53d7/A-Taste-of-Your-Own-Magic-Agents-of-A-S-S-E-T-2-by-Katie-Salidas.pdf
    • http://tanceubio.myhome.cx/13d23d63d03d13d7/Chasing-Chaos-Hollywood-Lights-3-by-Katie-Rose-Guest-Pryal.pdf
    • http://tanceubio.myhome.cx/13d03d43d93d53d63d7/Three-Down-the-Aisle-Rose-Cottage-Sisters-1-by-Sherryl-Woods.pdf
    • http://tanceubio.myhome.cx/13d03d43d93d63d43d5/What-s-Cooking-Rose-Cottage-Sisters-2-by-Sherryl-Woods.pdf
    • http://tanceubio.myhome.cx/23d13d93d33d13d2/Magic-of-Blood-and-Sea-The-Assassin-s-Curse-1-2-by-Cassandra-Rose-Clarke.pdf
    • http://tanceubio.myhome.cx/13d53d83d43d13d6/The-Magic-Goes-Away-Collection-The-Magic-Goes-Away-The-Magic-May-Return-More-Magic-by-Larry-Niven.pdf
    • http://tanceubio.myhome.cx/93d83d43d5/Chocolate-Covered-Katie-Over-80-Delicious-Recipes-That-Are-Secretly-Good-for-You-by-Katie-Higgins.pdf
    • http://tanceubio.myhome.cx/63d23d53d73d1/Kisses-from-Katie-A-Young-Woman-s-Journey-of-Faith-A-Remote-Village-A-Love-without-Limits-by-Katie-J-Davis.pdf
    • http://tanceubio.myhome.cx/73d33d63d13d73d3/Borderline-by-Robert-Appleton.pdf
    • http://tanceubio.myhome.cx/23d13d83d33d03d2/The-Mysterious-Lady-Law-by-Robert-Appleton.pdf
    • http://tanceubio.myhome.cx/13d03d63d93d93d43d7/Bethany-Sins-by-Alanna-Appleton.pdf
    • http://tanceubio.myhome.cx/13d13d43d33d23d13d3/Ein-unheimlicher-Passagier-by-George-Webb-Appleton.pdf
    • http://tanceubio.myhome.cx/23d63d23d33d93d8/Sweets-and-Treats-with-Six-Sisters-Stuff-100-Desserts-Gift-Ideas-and-Traditions-for-the-Whole-Family-by-Six-Sisters.pdf
    • http://tanceubio.myhome.cx/33d73d23d93d33d6/Kisses-from-Katie-by-Katie-J-Davis.pdf
    • http://tanceubio.myhome.cx/13d23d43d83d03d6/Greetings-Earthlings-My-name-is-Appleton-and-I-come-from-the-Planet-Reginta-by-J-Jack-Bergeron.pdf
    • http://tanceubio.myhome.cx/13d53d83d43d13d6/The-Magic-Goes-Away-Collection-The-Magic-Goes-Away-The-Magic-May-Return-More-Magic-by-Larry-Niven.pd