Malicious PDF — malware analysis report

Static analysis result for SHA-256 b64468ea679ccfa2…

MALICIOUS

PDF

18.9 KB Created: 2020-03-18 16:31:06 +00:00 Authoring application: mPDF 5.7
MD5: e1fd14faa3893eebff91cf2b60e7b4d0 SHA-1: a6a3d0791d01d2661f988b1c8ec72259851c5999 SHA-256: b64468ea679ccfa2a7e056c8a170ad8e6057a55aaff86ba2105808e2ca8416ee
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to external PDF files hosted on the same domain, suggesting a link farm or a distribution mechanism for malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/36a06a06a86a76a3/Hard-Core-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/26a66a26a56a36a7/Brothers-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/36a06a46a56a86a4/A-Little-Less-Girl-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/36a76a86a86a86a7/Strangely-Normal-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/86a46a06a86a6/Bitterroot-Crossing-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/16a46a86a56a86a2/Clutch-Custom-Culture-2-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/26a96a76a86a06a6/Rain-Shadow-Rainshadow-4-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/16a16a96a56a16a46a3/Seth-The-Barringer-Brothers-3-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/36a36a76a86a96a0/Paradise-Girl-Friday-1-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/16a16a96a56a16a26a3/Dirty-Shame-Bluefield-Bad-Boys-1-by-Tess-Oliver.pdf
    • http://rtuninnsi.myhome.cx/16a06a76a16a06a66a0/Tess-Gerritsen-Collection-The-Mephisto-Club-Call-After-Midnight-In-Their-Footsteps-Gravity-Whistleblower-Under-The-Knife-Stolen-Presumed-Guilty-Keeper-Of-The-Bride-by-Tess-Gerritsen.pdf
    • http://rtuninnsi.myhome.cx/26a16a16a66a36a2/The-Edge-of-Never-The-Edge-of-Always-Two-Book-Collection-The-Edge-of-Never-1-2-by-J-A-Redmerski.pdf
    • http://rtuninnsi.myhome.cx/16a06a06a46a4/The-Hard-Thing-About-Hard-Things-Building-a-Business-When-There-Are-No-Easy-Answers-by-Ben-Horowitz.pdf
    • http://rtuninnsi.myhome.cx/16a16a46a16a66a66a9/The-Boyfriend-List-15-Guys-11-Shrink-Appointments-4-Ceramic-Frogs-and-Me-Ruby-Oliver-Ruber-Oliver-1-by-E-Lockhart.pdf
    • http://rtuninnsi.myhome.cx/56a96a26a06a36a4/Hard-As-Steel-Hard-Ink-4-5-Raven-Riders-0-5-by-Laura-Kaye.pdf
    • http://rtuninnsi.myhome.cx/96a66a86a86a66a0/Beyond-Crunches-Hard-Science-Hard-ABS-by-Pavel-Tsatsouline.pdf
    • http://rtuninnsi.myhome.cx/16a46a56a96a96a3/Hard-to-Stop-Hard-Targets-3-by-Wendy-Byrne.pdf
    • http://rtuninnsi.myhome.cx/36a36a66a36a16a9/Hard-to-Hold-On-Hard-to-Resist-2-by-Shanora-Williams.pdf
    • http://rtuninnsi.myhome.cx/46a86a06a36a46a0/Hard-to-Hold-Hard-to-Play-1-by-Katie-Rose.pdf
    • http://rtuninnsi.myhome.cx/76a66a2/Hard-to-Be-Good-Hard-Ink-3-5-by-Laura-Kaye.pdf
    • http://rtuninnsi.myhome.cx/16a06a76a16a06a66a0/Tess-Gerritsen-Collection-The-Mephisto-Club-Call-After-Midnight-In-Their-Footsteps-Gravity-Whistleblower-Under-The-Knife-Stolen-Presumed-Guilty-Keeper-Of-The-Bride-by-Tess-