Malicious PDF — malware analysis report

Static analysis result for SHA-256 a4341ebe6a39e264…

MALICIOUS

PDF

21.4 KB Created: 2020-03-18 21:47:22 +00:00 Authoring application: mPDF 5.7
MD5: 1e641e5c442ee1a3832882e513af3b9c SHA-1: bb9b66f69eb7157f8abd426e517cce003dc4fcf7 SHA-256: a4341ebe6a39e264f0c9a174f5c49cc89392b479459984662f7cd6003d76efc2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, which likely serve as a lure to redirect users to malicious websites or download further malware. The document body itself is heavily obfuscated and does not provide clear textual content for analysis. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://peldoaio.myhome.cx/43d73d53d53d13d6/The-Hasheesh-Eater-Being-Passages-from-the-Life-of-a-Pythagorean-by-Fitz-Hugh-Ludlow.pdf
    • http://peldoaio.myhome.cx/43d13d33d13d73d0/The-Hasheesh-Eater-s-Companion-Accompanying-Fitz-Hugh-Ludlow-s-quot-the-Hasheesh-Eater-quot-by-David-M-Gross.pdf
    • http://peldoaio.myhome.cx/13d23d03d03d73d0/Awfully-Appetizing-The-Corpse-Eater-Saga-1-by-Leod-D-Fitz.pdf
    • http://peldoaio.myhome.cx/73d53d33d63d23d8/Life-s-Passages-From-Guyana-to-America-by-Erwin-K-Thomas.pdf
    • http://peldoaio.myhome.cx/93d83d63d93d13d4/A-Flat-Iron-for-a-Farthing-or-Some-Passages-in-the-Life-of-an-Only-Son-by-Juliana-Horatia-Ewing.pdf
    • http://peldoaio.myhome.cx/43d73d13d23d93d0/Talking-with-My-Mouth-Full-My-Life-as-a-Professional-Eater-by-Gail-Simmons.pdf
    • http://peldoaio.myhome.cx/93d93d13d73d63d3/Meat-Eater-Adventures-from-the-Life-of-an-American-Hunter-by-Steven-Rinella.pdf
    • http://peldoaio.myhome.cx/53d53d73d13d23d0/Select-Sentences-Of-Sextus-The-Pythagorean-by-Florence-Firth.pdf
    • http://peldoaio.myhome.cx/23d63d93d63d63d7/My-Life-With-Words-by-Hugh-Aaron.pdf
    • http://peldoaio.myhome.cx/13d53d13d73d3/The-Tree-of-Life-by-Hugh-Nissenson.pdf
    • http://peldoaio.myhome.cx/13d03d13d93d63d93d7/Hugh-Nibley-A-Consecrated-Life-by-Boyd-Jay-Petersen.pdf
    • http://peldoaio.myhome.cx/23d03d83d83d93d7/The-Sin-Eater-s-Daughter-The-Sin-Eater-s-Daughter-1-by-Melinda-Salisbury.pdf
    • http://peldoaio.myhome.cx/23d33d03d33d13d3/Dearest-Hugh-The-Courtship-Letters-of-Gabrielle-Drake-and-Hugh-McColl-1900-1901-by-Suzanne-Cameron-Linder-Hurley.pdf
    • http://peldoaio.myhome.cx/73d03d93d83d23d0/A-Manual-of-Faith-and-Life-A-Guide-for-Individual-Christians-or-Communicant-Classes-by-Hugh-T-Kerr.pdf
    • http://peldoaio.myhome.cx/13d73d03d03d43d9/alt-punk-by-Lavinia-Ludlow.pdf
    • http://peldoaio.myhome.cx/43d83d13d13d23d1/The-Trouble-with-Timothy-by-Margaret-Ludlow.pdf
    • http://peldoaio.myhome.cx/13d93d53d83d93d0/In-Search-of-Sir-Thomas-Browne-The-Life-and-Afterlife-of-the-Seventeenth-Century-s-Most-Inquiring-Mind-by-Hugh-Aldersey-Williams.pdf
    • http://peldoaio.myhome.cx/43d83d33d83d63d3/A-Children-s-Treasury-of-Verse-by-Patricia-Ludlow.pdf
    • http://peldoaio.myhome.cx/23d13d03d53d33d7/Temple-and-Cosmos-Beyond-This-Ignorant-Present-The-Collected-Works-of-Hugh-Nibley-Volume-12-by-Hugh-Nibley.pdf
    • http://peldoaio.myhome.cx/83d93d53d23d6/Hugh-Johnson-s-Wine-Companion-The-Encyclopedia-of-Wines-Vineyards-and-Winemakers-by-Hugh-Johnson.pdf
    • http://peldoaio.myhome.cx/93d93d13d73d63d3/Meat-Eater-