Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6387c755617f1d4…

MALICIOUS

PDF

18.7 KB Created: 2019-05-04 12:41:49 +01:00 Authoring application: mPDF 5.7
MD5: 215db9214d2801991aa9b887cc516adb SHA-1: 3885ea4cf9e142e3e3535741483db892bb63702f SHA-256: b6387c755617f1d4fa15b5d48bd9df5e524b2c2925d409283306492a149d87af
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links, such as 'http://zacdsa.linkpc.net/4c59c55c57/Baby-Fever-Bride-Baby-Fever-Love-1-by-Nicole-Snow.pdf', likely lead to malicious content or further downloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc.net/4c59c55c57/Baby-Fever-Bride-Baby-Fever-Love-1-by-Nicole-Snow.pdf
    • http://zacdsa.linkpc.net/1c50c53c58c54/Fever-Moon-The-Fear-Dorcha-Fever-5-5-by-Karen-Marie-Moning.pdf
    • http://zacdsa.linkpc.net/1c57c57c56c50c54/Love-Scars-Bad-Boy-s-Bride-by-Nicole-Snow.pdf
    • http://zacdsa.linkpc.net/3c59c52c55c56c52/Baby-Love-Baby-2-by-Andrea-Smith.pdf
    • http://zacdsa.linkpc.net/3c56c54c55c53c55/I-Love-Baby-Animals---Fun-Children-s-Picture-Book-with-Amazing-Photos-of-Baby-Animals-by-David-Chuka.pdf
    • http://zacdsa.linkpc.net/3c57c54c57c57c56/Love-Fever-by-J-S-Cooper.pdf
    • http://zacdsa.linkpc.net/6c50c56c55c56c58/Of-Love-and-Life-PS-I-Love-You-Fever-Hill-Secret-Smile-by-Cecelia-Ahern.pdf
    • http://zacdsa.linkpc.net/4c57c56c51c52c51/Fever-Pitch-Love-Lessons-2-by-Heidi-Cullinan.pdf
    • http://zacdsa.linkpc.net/2c58c56c51c58c54/Fever-Pitch-Love-Lessons-2-by-Heidi-Cullinan.pdf
    • http://zacdsa.linkpc.net/7c58c51c51c58c57/Baby-Blues-by-Nicole-Beaudry.pdf
    • http://zacdsa.linkpc.net/1c50c58c58c54c51c55/The-Baby-Deal-by-Jenika-Snow.pdf
    • http://zacdsa.linkpc.net/4c54c56c59c53c52/Orchid-Fever-A-Horticultural-Tale-of-Love-Lust-and-Lunacy-by-Eric-Hansen.pdf
    • http://zacdsa.linkpc.net/5c52c57c51c55/The-Adventures-Of-Baby-Crow-The-Search-For-Baby-Pigeon-by-Alex-Thomas-Davis.pdf
    • http://zacdsa.linkpc.net/3c59c59c55c58c50/Secrets-of-the-Baby-Whisperer-How-to-Calm-Connect-and-Communicate-with-Your-Baby-by-Tracy-Hogg.pdf
    • http://zacdsa.linkpc.net/9c54c54c58c50c58/Secrets-of-the-Baby-Whisperer-How-to-Calm-Connect-and-Communicate-with-Your-Baby-by-Tracy-Hogg.pdf
    • http://zacdsa.linkpc.net/4c50c53c53c51c55/Karen-s-Baby-Baby-Sitters-Little-Sister-Super-Special-5-by-Ann-M-Martin.pdf
    • http://zacdsa.linkpc.net/2c59c59c56c50c51/Trust-Fund-Baby-Frat-Boys-Baby-1-by-Aiden-Bates.pdf
    • http://zacdsa.linkpc.net/9c55c56c53c55c57/Real-Baby-Food-Easy-All-Natural-Recipes-for-Your-Baby-and-Toddler-by-Jenna-Helwig.pdf
    • http://zacdsa.linkpc.net/1c50c58c58c51c58c53/From-Baby-Boom-To-Baby-Bust-How-Business-Can-Meet-The-Demographic-Challenge-by-Martin-M-Greller.pdf
    • http://zacdsa.linkpc.net/2c55c56c58c58c59/Real-Food-for-Mother-and-Baby-The-Fertility-Diet-Eating-for-Two-and-Baby-s-First-Foods-by-Nina-Planck.pdf
    • http://zacdsa.linkpc.net/4c57c56c51