Malicious PDF — malware analysis report

Static analysis result for SHA-256 a60192a76493bd76…

MALICIOUS

PDF

21.0 KB Created: 2020-03-16 18:24:50 +00:00 Authoring application: mPDF 5.7
MD5: 47c1c0dba34192932370d8ef45271f23 SHA-1: 68fb6e5eddfe356b77b6581fd715241ccd5fd9f9 SHA-256: a60192a76493bd76a93b968d351590721fc612d76983d0bc5f57c68a73ddf73f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to redirect users to malicious content. The ML classifier strongly indicated maliciousness. The embedded URLs are the primary IOCs, and the heuristic suggests a link farm attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/33d53d23d73d63d2/The-Unsayable-The-Hidden-Language-of-Trauma-by-Annie-G-Rogers.pdf
    • http://tanceubio.myhome.cx/33d73d83d93d23d0/The-Unsayable-The-Hidden-Language-of-Trauma-by-Annie-G-Rogers.pdf
    • http://tanceubio.myhome.cx/53d13d93d43d23d8/Hidden-Lives-My-Three-Grandmothers-by-Carole-Garibaldi-Rogers.pdf
    • http://tanceubio.myhome.cx/23d33d83d53d23d4/Gone-Tomorrow-The-Hidden-Life-of-Garbage-by-Heather-Rogers.pdf
    • http://tanceubio.myhome.cx/13d33d83d03d23d9/Speech-Acts-An-Essay-in-the-Philosophy-of-Language-by-John-Rogers-Searle.pdf
    • http://tanceubio.myhome.cx/23d53d43d43d93d8/Mind-Language-And-Society-Philosophy-In-The-Real-World-by-John-Rogers-Searle.pdf
    • http://tanceubio.myhome.cx/43d83d13d13d1/The-Hidden-Coast-Kayak-Explorations-from-Alaska-to-Mexico-by-Joel-W-Rogers.pdf
    • http://tanceubio.myhome.cx/13d43d33d23d13d9/The-Body-Remembers-The-Psychophysiology-of-Trauma-and-Trauma-Treatment-by-Babette-Rothschild.pdf
    • http://tanceubio.myhome.cx/63d43d43d03d53d8/Healing-Developmental-Trauma-How-Early-Trauma-Affects-Self-Regulation-Self-Image-and-the-Capacity-for-Relationship-by-Laurence-Heller.pdf
    • http://tanceubio.myhome.cx/63d33d63d43d93d7/Buried-Treasure-Hidden-Wisdom-from-the-Hebrew-Language-by-Daniel-Lapin.pdf
    • http://tanceubio.myhome.cx/93d93d43d93d13d0/The-Code-of-the-City-Standards-and-the-Hidden-Language-of-Place-Making-by-Eran-Ben-Joseph.pdf
    • http://tanceubio.myhome.cx/53d83d33d73d23d7/The-Genesis-and-Geometry-of-the-Labyrinth-Architecture-Hidden-Language-Myths-and-Rituals-by-Patrick-Conty.pdf
    • http://tanceubio.myhome.cx/83d13d33d13d33d6/On-the-Essence-of-Language-The-Metaphysics-of-Language-and-the-Essencing-of-the-Word-Concerning-Herder-s-Treatise-on-the-Origin-of-Language-by-Martin-Heidegger.pdf
    • http://tanceubio.myhome.cx/13d03d63d03d53d43d8/Language-History-Language-Change-and-Language-Relationship-An-Introduction-to-Historical-and-Comparative-Linguistics-by-Hans-Henrich-Hock.pdf
    • http://tanceubio.myhome.cx/53d23d63d23d73d9/Annie-s-Verdict-Michael-Gresham-7-Annie-the-Profiler-1-by-John-Ellsworth.pdf
    • http://tanceubio.myhome.cx/53d13d83d33d6/Annie-and-the-Senator-Annie-Chan-Thrillers-1-by-Robert-W-McGee.pdf
    • http://tanceubio.myhome.cx/93d83d53d63d83d9/Sayonara-My-Friend-Love-Annie-by-Annie-Nenaka.pdf
    • http://tanceubio.myhome.cx/33d93d83d93d53d8/Trauma-Junkie-Trauma-Junkie-1-by-Tom-Hobbs.pdf
    • http://tanceubio.myhome.cx/43d53d33d63d83d2/The-Secret-Language-of-Dogs-The-Body-Language-of-Furry-Bodies-by-Heather-Dunphy.pdf
    • http://tanceubio.myhome.cx/43d83d73d03d93d2/Secret-Language-of-Cats-The-Body-Language-of-Feline-Bodies-by-Heather-Dunphy.pdf
    • http://tanceubio.myhome.cx/63d43d43d03d53d8/Healing-Developmental-Trauma-How-Early-Trauma-Affects-Self-Regulation-Self-I