Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9ea0c7e054bef15…

MALICIOUS

PDF

21.0 KB Created: 2020-02-15 01:39:24 +00:00 Authoring application: mPDF 5.7
MD5: f25ac1dac2d9c8fee5b6647a77ee338b SHA-1: 4d3d002e7b327aa3829e7f4cc360e86a1047fbb0 SHA-256: a9ea0c7e054bef15c478a0d9b2264d68c6d67a016813c91054c90c5b6c42c58e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary purpose appears to be hosting a link farm, likely to manipulate search engine results or redirect users to potentially malicious content hosted at the listed URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tuiwckiko.jpn.ph/45d45d65d75d05d4/Serial-Love-Saints-Protection-amp-Investigations-1-by-Maryann-Jordan.pdf
    • http://tuiwckiko.jpn.ph/45d45d65d75d05d0/Remember-Love-Saints-Protection-amp-Investigations-8-by-Maryann-Jordan.pdf
    • http://tuiwckiko.jpn.ph/15d45d65d95d75d9/Love-s-Tempting-The-Love-s-2-by-Maryann-Jordan.pdf
    • http://tuiwckiko.jpn.ph/25d25d25d85d95d3/Vinny-Alvarez-Security-3-by-Maryann-Jordan.pdf
    • http://tuiwckiko.jpn.ph/45d55d95d25d25d9/Emma-s-Home-Fairfield-1-by-Maryann-Jordan.pdf
    • http://tuiwckiko.jpn.ph/15d05d25d25d55d45d4/Waiting-for-Sunrise-Baytown-Boys-Series-by-Maryann-Jordan.pdf
    • http://tuiwckiko.jpn.ph/25d75d15d15d75d7/Belonging-Places---Every-woman-s-story-on-life-lessons-and-love-by-Maryann-Weston.pdf
    • http://tuiwckiko.jpn.ph/35d55d25d15d35d3/Love-Like-Ghosts-Bay-City-Paranormal-Investigations-7-by-Ally-Blue.pdf
    • http://tuiwckiko.jpn.ph/35d65d65d55d45d6/All-Saints-Daily-Reflections-on-Saints-Prophets-amp-Witnesses-for-Our-Time-by-Robert-Ellsberg.pdf
    • http://tuiwckiko.jpn.ph/45d55d35d05d85d6/Saints-Alive-New-Stories-of-Old-Saints-Volume-II-Celtic-Paths-by-Andrew-M-Seddon.pdf
    • http://tuiwckiko.jpn.ph/45d55d65d65d85d8/Original-Sin-Dark-Saints-Motorcycle-Club-1-by-Amy-Love.pdf
    • http://tuiwckiko.jpn.ph/25d05d65d25d85d4/Saints-United-For-Love-of-Authority-3-by-Rhiannon-Ayers.pdf
    • http://tuiwckiko.jpn.ph/15d45d85d05d7/Saints-Boxers-amp-Saints-2-by-Gene-Luen-Yang.pdf
    • http://tuiwckiko.jpn.ph/65d55d45d45d4/The-Serial-Killer-Books-15-Famous-Serial-Killers-True-Crime-Stories-That-Shocked-The-World-by-Jack-Rosewood.pdf
    • http://tuiwckiko.jpn.ph/75d15d85d15d25d5/Rapport-d-information-sur-l-accord-de-protection-des-donn-es-personnelles-quot-Bouclier-de-protection-quot-entre-les-Etats-Unis-d-Am-rique-et-l-Union-europ-enne-des-donn-es-personnelles-by-Assembl-e-nationale.pdf
    • http://tuiwckiko.jpn.ph/15d05d85d75d35d85d2/Altruistic-Love-A-Study-of-American-Good-Neighbors-and-Christian-Saints-by-Pitirim-A-Sorokin.pdf
    • http://tuiwckiko.jpn.ph/25d95d15d95d45d6/Serial-Volume-One-Serial-1-by-Jaden-Wilkes.pdf
    • http://tuiwckiko.jpn.ph/15d15d95d55d85d7/Why-We-Love-Serial-Killers-The-Curious-Appeal-of-the-World-s-Most-Savage-Murderers-by-Scott-A-Bonn.pdf
    • http://tuiwckiko.jpn.ph/75d05d35d55d6/Love-at-Last-Sight-by-Jordan-Lynde.pdf
    • http://tuiwckiko.jpn.ph/35d15d95d15d35d4/Love-Me-or-Miss-Me-Hot-Girl-Bad-Boy-by-Dream-Jordan.pdf
    • http://tuiwckiko.jpn.ph/35d65d65d55d45d6/A