Malicious PDF — malware analysis report

Static analysis result for SHA-256 890917470659b2c4…

MALICIOUS

PDF

14.5 KB Created: 2019-04-30 04:04:09 +01:00 Authoring application: mPDF 5.7
MD5: ea92e0e3027eeedff700d4a0f40a3cf6 SHA-1: 7917d187417963f5c0c28e961b3f91b4b53100d0 SHA-256: 890917470659b2c4fd686b5e35d4628cf05cf185232d63418dbf67f0c50804ef
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, all hosted on the same dynamic DNS domain. This pattern is indicative of SEO spam or a distribution point for malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted, and the document body primarily consists of these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4202204202200202/Wolf-Town-Mates-Wolf-Town-1-3-by-Joely-Skye.pdf
    • http://xiixmcuin.linkpc.net/3203202200200207/Wolf-Town-Wolf-Town-1-by-Joely-Skye.pdf
    • http://xiixmcuin.linkpc.net/5209206207202/My-Wolf-King-Wolf-Town-Guardians-1-by-Rose-Wynters.pdf
    • http://xiixmcuin.linkpc.net/1202203205207207/My-Wolf-Protector-Wolf-Town-Guardians-2-by-Rose-Wynters.pdf
    • http://xiixmcuin.linkpc.net/1201209207202202208/Bree-Wolf-Run-Romancing-the-Wolf-1-by-Skye-Eagleday.pdf
    • http://xiixmcuin.linkpc.net/6208207202209204/What-s-New-Pussycat-Wolf-Mates-2-by-Dakota-Cassidy.pdf
    • http://xiixmcuin.linkpc.net/8204204203201209/Cinder-Wolf-The-Wolf-Wanderers-1-by-Terra-Wolf.pdf
    • http://xiixmcuin.linkpc.net/2201205209209203/Low-Town-Low-Town-1-by-Daniel-Polansky.pdf
    • http://xiixmcuin.linkpc.net/4202207205207203/Tempted-by-the-Wolf-True-Mates-6-by-Alicia-Montgomery.pdf
    • http://xiixmcuin.linkpc.net/3206205204203206/Pack-Ebon-Red-The-Seven-Mates-of-Zara-Wolf-1-by-C-M-Stunich.pdf
    • http://xiixmcuin.linkpc.net/2209209203206205/Blaze-Dragon-s-Destiny-Fated-Mates-4-by-Wolf-Specter.pdf
    • http://xiixmcuin.linkpc.net/2209209204206204/Scorch-Dragon-s-Destiny-Fated-Mates-2-by-Wolf-Specter.pdf
    • http://xiixmcuin.linkpc.net/1207204205201204/Hungry-for-Her-Mates-Wolf-s-Pass-Shifters-2-by-Marla-Monroe.pdf
    • http://xiixmcuin.linkpc.net/1200209204209209/Escape-to-Clown-Town-Clown-Town-Adventures-1-by-Tephra-Miriam.pdf
    • http://xiixmcuin.linkpc.net/1208204204205207/Crying-Wolf-Black-River-Pack-1-Fated-Mates-1-by-Rochelle-Paige.pdf
    • http://xiixmcuin.linkpc.net/3208208204200208/Abbey-s-Protectors-Beckett-s-Wolf-Pack-Triad-Mates-4-by-Lynnette-Bernard.pdf
    • http://xiixmcuin.linkpc.net/2207208205200206/Running-Wild-Northern-Shifters-4-by-Joely-Skye.pdf
    • http://xiixmcuin.linkpc.net/3206205200206205/Tales-of-the-Wolf-Fifty-One-Stories-of-Wolf-Encounters-in-the-Wild-by-Tim-W-Clark.pdf
    • http://xiixmcuin.linkpc.net/2203206206200200/A-Wolf-in-Wolf-s-Clothing-Sisters-of-Colford-Hall-3-by-Deborah-Macgillivray.pdf
    • http://xiixmcuin.linkpc.net/3208200201208203/Summit-of-the-Wolf-Silver-Wolf-Clan-4-by-Tera-Shanley.pdf
    • http://xiixmcuin.linkpc.net/12002