Malicious PDF — malware analysis report

Static analysis result for SHA-256 560494c5d5065fcc…

MALICIOUS

PDF

21.0 KB Created: 2020-03-18 16:33:31 +00:00 Authoring application: mPDF 5.7
MD5: ec272b7a5cb4ba7fd7caa56711b7f0d7 SHA-1: 18a9f41802eb4deee8a2636d1146e8be09b20e16 SHA-256: 560494c5d5065fcca34b5519d31a4832439eea88295922f6ba3b6abb2968bba6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9805

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/5552554553558554/Falling-for-the-Billionaire-The-Complete-Series-Falling-for-the-Billionaire-1-3-by-Victoria-Villeneuve.pdf
    • http://ieuicufioao.myhome.cx/5552554554550556/Claimed-The-Billionaire-s-Command-2-by-Victoria-Villeneuve.pdf
    • http://ieuicufioao.myhome.cx/4557559556557557/Falling-for-the-Billionaire-One-Night-Stand-4-by-J-S-Cooper.pdf
    • http://ieuicufioao.myhome.cx/5552554554551552/Running-from-Reality-Running-from-the-Billionaire-1-by-Victoria-Villeneuve.pdf
    • http://ieuicufioao.myhome.cx/4557554551/The-Billionaire-s-Christmas-Virgin-Prelude-to-Billionaire-Unknown---Blake-The-Billionaire-s-Obsession-9-5-by-J-S-Scott.pdf
    • http://ieuicufioao.myhome.cx/2555553551558553/The-Billionaire-s-Desire-The-Complete-Series-by-Cassie-Cross.pdf
    • http://ieuicufioao.myhome.cx/9556554556550/Falling-in-Fiji-Falling-in-Paradise-1-by-Casey-Hagen.pdf
    • http://ieuicufioao.myhome.cx/5559556554550550/Falling-for-the-Colonel-by-Victoria-Hart.pdf
    • http://ieuicufioao.myhome.cx/4554550557550554/The-Billionaire-s-Marriage-Con-A-Clean-Billionaire-Romance-The-Kinlans-Trilogy-Book-3-by-Alicia-Eve.pdf
    • http://ieuicufioao.myhome.cx/2555551559551550/Lexie-s-First-Time-Borrowed-Billionaire-0-5-Billionaire-Novelist-0-5-by-Mimi-Strong.pdf
    • http://ieuicufioao.myhome.cx/2552557554551551/The-Billionaire-Shifter-s-Second-Chance-Billionaire-Shifters-Club-3-by-Diana-Seere.pdf
    • http://ieuicufioao.myhome.cx/4554550556557552/The-Broke-Billionaire-Clean-Billionaire-Beach-Club-Romance-Book-7-by-Bonnie-R-Paulson.pdf
    • http://ieuicufioao.myhome.cx/4554550556558558/The-Brazen-Billionaire-Clean-Billionaire-Beach-Club-Romance-Book-4-by-Elana-Johnson.pdf
    • http://ieuicufioao.myhome.cx/3554552552554554/Falling-into-Forever-Falling-into-You-2-by-Lauren-Abrams.pdf
    • http://ieuicufioao.myhome.cx/3559557557558551/The-Falling-of-Hope-Falling-3-by-Marisa-Oldham.pdf
    • http://ieuicufioao.myhome.cx/9558556559554551/Edge-of-Falling-Falling-2-by-Valia-Lind.pdf
    • http://ieuicufioao.myhome.cx/1550551554559557/The-Falling-of-Love-Falling-1-by-Marisa-Oldham.pdf
    • http://ieuicufioao.myhome.cx/4554550556559553/Mending-Images-with-the-Billionaire-A-Clean-Billionaire-Romance-Artists-amp-Billionaires-Book-4-by-Lorin-Grace.pdf
    • http://ieuicufioao.myhome.cx/4553553558556553/The-Billionaire-Cowboy-Billionaire-s-Club-Texas-1-by-Mandy-Baxter.pdf
    • http://ieuicufioao.myhome.cx/1554554555554557/The-Billionaire-s-Final-Stand-Billionaire-Bachelors-7-by-Melody-Anne.pdf