Malicious PDF — malware analysis report

Static analysis result for SHA-256 52f162109c91e7ff…

MALICIOUS

PDF

21.4 KB Created: 2020-03-18 17:38:40 +00:00 Authoring application: mPDF 5.7
MD5: 8bed26e94612de4295a5cbdce38ebe17 SHA-1: 77572fd08695a7479d41fd606a5e7a6b5e67aa72 SHA-256: 52f162109c91e7ffcbbee8aff9d9c5ffc5ed12bbcf4e48ca446edf7ace2f65e5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, hosted on a suspicious domain. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/63d93d43d73d53d9/Woman-of-Color-Daughter-of-Privilege-Amanda-America-Dickson-1849-1893-by-Kent-Anderson-Leslie.pdf
    • http://tanceubio.myhome.cx/23d53d23d63d6/A-Man-of-Privilege-Lawyers-in-Love-2-by-Sarah-M-Anderson.pdf
    • http://tanceubio.myhome.cx/63d93d43d73d83d2/Wake-Up-to-a-Happier-Life-Finding-Joy-in-the-Work-You-Do-Every-Day-by-Amanda-Dickson.pdf
    • http://tanceubio.myhome.cx/13d13d13d23d73d83d8/Casper-and-Catherine-Move-to-America-An-Immigrant-Family-s-Adventures-1849-1850-by-Brian-Hasler.pdf
    • http://tanceubio.myhome.cx/43d43d73d33d23d0/America-at-the-Fair-Chicago-s-1893-World-s-Columbian-Exposition-by-Chaim-M-Rosenberg.pdf
    • http://tanceubio.myhome.cx/13d63d13d33d43d5/Griffin-s-Daughter-Griffin-s-Daughter-Trilogy-1-by-Leslie-Ann-Moore.pdf
    • http://tanceubio.myhome.cx/33d03d33d23d53d3/The-Heretic-s-Daughter-by-Kathleen-Kent.pdf
    • http://tanceubio.myhome.cx/43d73d23d53d63d6/The-Kindness-of-Bones-by-Leslie-Jane-Anderson.pdf
    • http://tanceubio.myhome.cx/23d13d53d33d43d6/Bending-Toward-the-Sun-A-Mother-and-Daughter-Memoir-by-Leslie-Gilbert-Lurie.pdf
    • http://tanceubio.myhome.cx/33d63d03d13d03d1/Shadow-Defenders-MC-1-by-Amanda-Anderson.pdf
    • http://tanceubio.myhome.cx/13d53d73d73d63d8/A-Woman-of-Consequence-A-Dido-Kent-Mystery-3-by-Anna-Dean.pdf
    • http://tanceubio.myhome.cx/83d03d33d03d23d3/The-Woman-in-White-Color-Illustrated-Formatted-for-E-Readers-by-Wilkie-Collins.pdf
    • http://tanceubio.myhome.cx/13d03d73d53d03d23d3/Nameless-Woman-An-Anthology-of-Fiction-by-Trans-Women-of-Color-by-Ellyn-Pe-a.pdf
    • http://tanceubio.myhome.cx/23d23d73d93d63d5/Pawnee-The-Greatest-Town-in-America-by-Leslie-Knope.pdf
    • http://tanceubio.myhome.cx/33d73d13d33d43d7/The-Color-of-War-How-One-Battle-Broke-Japan-and-Another-Changed-America-by-James-Campbell.pdf
    • http://tanceubio.myhome.cx/43d13d53d93d93d9/The-Color-of-Law-A-Forgotten-History-of-How-Our-Government-Segregated-America-by-Richard-Rothstein.pdf
    • http://tanceubio.myhome.cx/73d43d03d93d03d9/Understanding-Human-Differences-Multicultural-Education-for-a-Diverse-America-by-Kent-L-Koppelman.pdf
    • http://tanceubio.myhome.cx/33d43d33d43d83d9/Consuelo-and-Alva-Vanderbilt-The-Story-of-a-Daughter-and-a-Mother-in-the-Gilded-Age-by-Amanda-Mackenzie-Stuart.pdf
    • http://tanceubio.myhome.cx/53d83d63d93d8/Courage-Has-No-Color-The-True-Story-of-the-Triple-Nickles-America-s-First-Black-Paratroopers-by-Tanya-Lee-Stone.pdf
    • http://tanceubio.myhome.cx/23d33d93d53d93d6/Griffin-s-Shadow-Griffin-s-Daughter-Trilogy-2-by-Leslie-Ann-Moore.pdf
    • http://tanceubio.myhome.cx/33d0