Malicious PDF — malware analysis report

Static analysis result for SHA-256 d22f428117699424…

MALICIOUS

PDF

17.8 KB Created: 2020-02-15 03:13:54 +00:00 Authoring application: mPDF 5.7
MD5: 38c67ae4cc026d298e3496a690d6b430 SHA-1: 9752421cde704aded5ca307810011ce2ac80a757 SHA-256: d22f428117699424cb8f844a5fbe47892cda3f3d366d511b1c47c04d65944478
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection tactic. ClamAV detected this file as Pdf.Dropper.Agent-7612183-0, and an ML classifier also flagged it as malicious. The embedded URLs are likely used to redirect users to malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7612183-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7612183-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lwoscmobook.myhome.cx/252435241524352405246/Once-Upon-a-True-Love-s-Kiss-by-Julie-Johnstone.pdf
    • http://lwoscmobook.myhome.cx/252455242524252455247/The-Last-Kiss-A-True-Story-of-Love-Joy-and-Loss-by-Leslie-Brody.pdf
    • http://lwoscmobook.myhome.cx/252445249524952425247/My-Enchanting-Hoyden-Once-Upon-a-Rogue-3-by-Julie-Johnstone.pdf
    • http://lwoscmobook.myhome.cx/452475245524252415243/When-a-Laird-Loves-a-Lady-Highlander-Vows-Entangled-Hearts-Book-1-by-Julie-Johnstone.pdf
    • http://lwoscmobook.myhome.cx/552425241524352465244/Kiss-Me-Awake-by-Julie-Momyer.pdf
    • http://lwoscmobook.myhome.cx/252485244524052425245/Aphrodite-s-Kiss-Superhero-Central-1-by-Julie-Kenner.pdf
    • http://lwoscmobook.myhome.cx/15241524352495245/Tremaine-s-True-Love-True-Gentlemen-1-by-Grace-Burrowes.pdf
    • http://lwoscmobook.myhome.cx/252425244524652415247/True-Luck-True-Love-1-by-Anyta-Sunday.pdf
    • http://lwoscmobook.myhome.cx/152425241524452445242/Kiss-Billie-for-Me-XXX-A-True-Story-by-Jeanette-Gray.pdf
    • http://lwoscmobook.myhome.cx/852415241524452435246/Love-by-Deception-A-harrowing-true-story-of-love-and-betrayal-by-K-C-Barnard.pdf
    • http://lwoscmobook.myhome.cx/552415249524652475243/Adventure-with-a-Glass-Eye-the-true-story-of-Graham-Laycock-s-extraordinary-vision-by-Julie-Anita-Raymond.pdf
    • http://lwoscmobook.myhome.cx/152475242524052405240/I-Love-You-Phillip-Morris-A-True-Story-of-Life-Love-amp-Prison-Breaks-by-Steve-McVicker.pdf
    • http://lwoscmobook.myhome.cx/452495248524452435244/True-Love-Caitlin-Love-Trilogy-3-by-Francine-Pascal.pdf
    • http://lwoscmobook.myhome.cx/252455248524652405248/Love-Me-Softly-by-Julie-Jameson.pdf
    • http://lwoscmobook.myhome.cx/252485242524052465248/Not-You-It-s-Me-Boston-Love-1-by-Julie-Johnson.pdf
    • http://lwoscmobook.myhome.cx/352465245524452415246/After-the-Kiss-Sex-Love-amp-Stiletto-1-by-Lauren-Layne.pdf
    • http://lwoscmobook.myhome.cx/452475247524352415245/Tripped-Up-Love-The-New-Ever-After-Series-1-by-Julie-Farley.pdf
    • http://lwoscmobook.myhome.cx/252485242524352415249/Rushing-Amy-Love-and-Football-2-by-Julie-Brannagh.pdf
    • http://lwoscmobook.myhome.cx/552405240524352435248/Pretend-You-Love-Me-by-Julie-Anne-Peters.pdf
    • http://lwoscmobook.myhome.cx/652445245524052455243/My-Love-My-Kiss-My-Heart-by-Arum-Puspa-Amalia.pdf
    • http://lwoscmobook.myhome.cx/85241524152445243524