Malicious PDF — malware analysis report

Static analysis result for SHA-256 55e8f4a8fa3cbc9b…

MALICIOUS

PDF

19.7 KB Created: 2020-03-05 09:46:11 +00:00 Authoring application: mPDF 5.7
MD5: cd7fad97e5668852b73dc666bf06ef85 SHA-1: f2382e98554c238fb204fa88369d785cfe9c142e SHA-256: 55e8f4a8fa3cbc9b1fe59209b882e25990a2b45372a89723ee6bde16226d2b0e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier and contains a large number of embedded URLs, indicating a potential SEO link farm or a distribution point for malicious content. The URLs point to various PDF files, suggesting a lure or redirection mechanism. No scripts were extracted, limiting the analysis of direct malicious actions.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/13d43d73d33d43d6/Doctor-Who-The-Tenth-Doctor-Facing-Fate-Vol-2-Vortex-Butterflies-by-Nick-Abadzis.pdf
    • http://tanceubio.myhome.cx/13d43d63d53d53d4/Doctor-Who-The-Tenth-Doctor-Complete-Year-One-by-Nick-Abadzis.pdf
    • http://tanceubio.myhome.cx/33d63d63d43d33d5/Doctor-Who-The-Tenth-Doctor-2-by-Nick-Abadzis.pdf
    • http://tanceubio.myhome.cx/33d63d63d13d73d9/Doctor-Who-The-Tenth-Doctor-3-by-Nick-Abadzis.pdf
    • http://tanceubio.myhome.cx/43d03d23d73d73d3/The-Doctor-s-New-Boy-and-Doctor-s-Orders-Books-One-and-Two-The-Dominant-Doctor-Book-1-by-Sammy-D-Adams.pdf
    • http://tanceubio.myhome.cx/23d93d43d63d93d7/Doctor-Who-The-Road-to-the-Thirteenth-Doctor-3-The-Twelfth-Doctor-by-James-Peaty.pdf
    • http://tanceubio.myhome.cx/23d13d13d13d33d8/Doctor-Who-Timeframe-The-Illustrated-History-Doctor-Who-30th-Anniversary-by-David-J-Howe.pdf
    • http://tanceubio.myhome.cx/73d83d93d03d73d3/Invisible-Anna-The-Doctor-s-Casebook-Doctor-and-Nurse-First-time-Romance-by-Liv-Jonasson.pdf
    • http://tanceubio.myhome.cx/33d53d13d23d33d4/Curing-Doctor-Vincent-The-Good-Doctor-Trilogy-1-by-Renea-Mason.pdf
    • http://tanceubio.myhome.cx/43d13d13d83d53d9/A-Big-Hand-for-The-Doctor-Doctor-Who-50th-Anniversary-E-Shorts-1-by-Eoin-Colfer.pdf
    • http://tanceubio.myhome.cx/23d03d63d23d73d2/Loving-Doctor-Vincent-The-Good-Doctor-Trilogy-3-by-Renea-Mason.pdf
    • http://tanceubio.myhome.cx/13d03d53d93d43d53d2/Doctor-Who-Something-Borrowed-Sixth-Doctor-50th-Anniversary-by-Richelle-Mead.pdf
    • http://tanceubio.myhome.cx/33d23d73d73d03d6/Doctor-Who-Short-Trips-How-the-Doctor-Changed-My-Life-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/53d53d03d33d83d8/Doctor-Who-Shadow-of-Death-Destiny-of-the-Doctor-2-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/23d03d83d13d83d3/Doctor-Who-Hunters-of-Earth-Destiny-of-the-Doctor-1-by-Nigel-Robinson.pdf
    • http://tanceubio.myhome.cx/43d93d03d83d23d6/The-Official-Quotable-Doctor-Who-The-Wit-and-Wisdom-of-Doctor-Who-by-Cavan-Scott.pdf
    • http://tanceubio.myhome.cx/63d43d23d33d13d7/Doctor-Dolittle-and-Tommy-Stubbins-A-Doctor-Dolittle-Chapter-Book-Doctor-Dolittle-Chapter-Books-by-N-H-Kleinbaum.pdf
    • http://tanceubio.myhome.cx/13d03d63d53d43d83d7/Doctor-Who---Zeitreisen-3-St-ndiger-Wettbewerb-by-Nick-Harkaway.pdf
    • http://tanceubio.myhome.cx/73d83d93d03d43d3/Kelly-and-the-Doctor-s-Visit-A-Backdoor-MfM-Menage-Medical-Fetish-Erotic-Story-The-Doctor-s-Travels-Book-2-by-Liv-Jonasson.pdf
    • http://tanceubio.myhome.cx/13d43d63d83d83d7/Doctor-Who-The-Eleventh-Doctor-Complete-Year-One-by-Al-Ewing.pdf
    • http://tanceubio.myhome.cx