Malicious PDF — malware analysis report

Static analysis result for SHA-256 67529df0db2dd470…

MALICIOUS

PDF

17.5 KB Created: 2020-03-15 10:30:41 +00:00 Authoring application: mPDF 5.7
MD5: edb9b78b6580c42c00211c2d71285dbc SHA-1: b4d9a0c92a8d43c100d17f0fc22c8b3d13b30078 SHA-256: 67529df0db2dd470242e630da8cabd04c34719d980697f996338e57b2e73c282
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, many of which are structured as book titles, suggesting a link farm designed to redirect users to external content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely to deliver a second-stage payload via these links. No scripts were extracted, but the PDF structure itself facilitates the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7780778-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7780778-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/7879873870879/Sweet-Possession-Sweet-5-by-Maya-Banks.pdf
    • http://kitasdyu.myhome.cx/7879878878872/Sweet-Temptation-Sweet-4-by-Maya-Banks.pdf
    • http://kitasdyu.myhome.cx/7878876876877/Sweet-Addiction-Sweet-6-by-Maya-Banks.pdf
    • http://kitasdyu.myhome.cx/1874873873874879/The-Reserve-by-Russell-Banks.pdf
    • http://kitasdyu.myhome.cx/4874870870874870/Trailerpark-by-Russell-Banks.pdf
    • http://kitasdyu.myhome.cx/1874870873873873/The-Angel-on-the-Roof-by-Russell-Banks.pdf
    • http://kitasdyu.myhome.cx/7875877875876877/The-Conde-Nast-Traveler-Book-of-Unforgettable-Journeys-Great-Writers-on-Great-Places-by-Russell-Banks.pdf
    • http://kitasdyu.myhome.cx/4874873875871878/Loving-an-Eaton-Sweet-Persuasions-Sweet-Destiny-by-Rochelle-Alers.pdf
    • http://kitasdyu.myhome.cx/8874876870870877/Lizzy-and-the-Magic-Coat-Sweet-Sweet-Dreams-by-Taliba-Morgan.pdf
    • http://kitasdyu.myhome.cx/3878877876870873/Sweet-Vengeance-Jessica-Sweet-Trilogy-1-by-Aliya-DalRae.pdf
    • http://kitasdyu.myhome.cx/2871877872877870/Sweet-Tea-at-Sunrise-The-Sweet-Magnolias-6-by-Sherryl-Woods.pdf
    • http://kitasdyu.myhome.cx/3873873871871879/Sweet-Evil-The-Sweet-Trilogy-1-by-Wendy-Higgins.pdf
    • http://kitasdyu.myhome.cx/2871876875874877/Sweet-Memories-Love-So-Sweet-1-by-Steena-Holmes.pdf
    • http://kitasdyu.myhome.cx/2875876873874873/Sweet-Rome-Sweet-Home-1-5-by-Tillie-Cole.pdf
    • http://kitasdyu.myhome.cx/1878877873876879/Sweet-Evil-The-Sweet-Trilogy-1-by-Wendy-Higgins.pdf
    • http://kitasdyu.myhome.cx/1870879878873/The-Sweet-Spot-Sweet-on-a-Cowboy-1-by-Laura-Drake.pdf
    • http://kitasdyu.myhome.cx/7870876873878877/Sweet-Masterpiece-Samantha-Sweet-1-by-Connie-Shelton.pdf
    • http://kitasdyu.myhome.cx/2879873874872872/Sophie-s-Sweet-Seduction-Sweet-Temptations-3-by-L-J-Anderson.pdf
    • http://kitasdyu.myhome.cx/6870877878871874/Sweet-s-Hortus-Britannicus-Or-a-Catalogue-of-Plants-Cultivated-in-the-Gardens-of-Great-Britain-Arranged-in-Natural-Orders-Volume-PT-12-by-Robert-Sweet.pdf
    • http://kitasdyu.myhome.cx/6870877878871877/Sweet-s-Hortus-Britannicus-Or-a-Catalogue-of-Plants-Indigenous-or-Cultivated-in-the-Gardens-of-Great-Britain-Arranged-According-to-the-Natural-System-by-Robert-Sweet.pdf