Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2a21eb6aed90e53…

MALICIOUS

PDF

25.2 KB Created: 2020-03-18 17:40:50 +00:00 Authoring application: mPDF 5.7
MD5: 42b615af9242970fa76572f2ff7be4f7 SHA-1: bb3e2388455b4c1d000612a0dfb6ea85e6059052 SHA-256: b2a21eb6aed90e533318169fe2a408d9c1ecd22aa7902111bf9d3590a7ab1bbe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files on a suspicious domain, indicative of a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a multitude of potentially malicious or unwanted content via these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tikytsesapdf.myhome.cx/278c378c878c578c278c9/The-Royal-Art-of-Poison-Filthy-Palaces-Fatal-Cosmetics-Deadly-Medicine-and-Murder-Most-Foul-by-Eleanor-Herman.pdf
    • http://tikytsesapdf.myhome.cx/178c678c778c378c278c0/Royal-Murder-The-Deadly-Intrigue-of-Ten-Sovereigns-by-Elizabeth-MacLeod.pdf
    • http://tikytsesapdf.myhome.cx/178c078c678c178c8/Fighting-the-Devil-A-True-Story-of-Consuming-Passion-Deadly-Poison-and-Murder-by-Jeannie-Walker.pdf
    • http://tikytsesapdf.myhome.cx/878c078c678c678c378c1/The-Fatal-Series-Volume-2-Fatal-Destiny-Fatal-Flaw-Fatal-Deception-Fatal-Mistake-Fatal-3-5-6-by-Marie-Force.pdf
    • http://tikytsesapdf.myhome.cx/678c678c978c878c578c8/Within-Royal-Palaces-A-Brilliant-and-Charmingly-Written-Inner-Life-View-by-Marquise-de-Fontenoy.pdf
    • http://tikytsesapdf.myhome.cx/678c878c678c778c678c6/Art-of-the-Royal-Court-Treasures-in-Pietre-Dure-from-the-Palaces-of-Europe-by-Annamaria-Giusti.pdf
    • http://tikytsesapdf.myhome.cx/378c278c478c178c578c8/Terrible-True-Tales-from-the-Tower-of-London-As-Told-by-the-Ravens-by-Historic-Royal-Palaces.pdf
    • http://tikytsesapdf.myhome.cx/778c678c078c678c578c4/Fatal-Remains-Marti-MacAlister-11-by-Eleanor-Taylor-Bland.pdf
    • http://tikytsesapdf.myhome.cx/278c978c478c478c678c8/Dawn-of-Legends-Blood-of-Gods-and-Royals-4-by-Eleanor-Herman.pdf
    • http://tikytsesapdf.myhome.cx/278c178c978c278c078c1/Reign-of-Serpents-Blood-of-Gods-and-Royals-3-by-Eleanor-Herman.pdf
    • http://tikytsesapdf.myhome.cx/178c478c278c5/Legacy-of-Kings-Blood-of-Gods-and-Royals-1-by-Eleanor-Herman.pdf
    • http://tikytsesapdf.myhome.cx/878c778c378c178c1/Poison-s-Kiss-Deadly-Beauties-2-by-C-M-Owens.pdf
    • http://tikytsesapdf.myhome.cx/278c378c978c078c278c4/Murder-Most-Foul-The-Killer-and-the-American-Gothic-Imagination-by-Karen-Halttunen.pdf
    • http://tikytsesapdf.myhome.cx/278c178c778c878c278c9/Jolly-Foul-Play-Murder-Most-Unladylike-Mysteries-4-by-Robin-Stevens.pdf
    • http://tikytsesapdf.myhome.cx/378c578c478c2/Poison-or-Protect-Delightfully-Deadly-1-by-Gail-Carriger.pdf
    • http://tikytsesapdf.myhome.cx/678c478c378c578c3/Mistress-of-the-Vatican-The-True-Story-of-Olimpia-Maidalchini-The-Secret-Female-Pope-by-Eleanor-Herman.pdf
    • http://tikytsesapdf.myhome.cx/278c578c278c178c278c8/Mistress-of-the-Vatican-The-True-Story-of-Olimpia-Maidalchini-The-Secret-Female-Pope-by-Eleanor-Herman.pdf
    • http://tikytsesapdf.myhome.cx/478c378c478c078c678c9/Some-Like-It-Deadly-Going-Royal-3-by-Heather-Long.pdf
    • http://tikytsesapdf.myhome.cx/478c078c878c278c078c7/Voice-of-Gods-Blood-of-Gods-and-Royals-0-5-by-Eleanor-Herman.pdf
    • http://tikytsesapdf.myhome.cx/378c278c578c178c778c7/Voice-of-Gods-Blood-of-Gods-and-Royals-0-5-by-Eleanor-Herman.pdf