Malicious PDF — malware analysis report

Static analysis result for SHA-256 d7d4ccf77bada7db…

MALICIOUS

PDF

20.5 KB Created: 2019-05-02 17:28:42 +01:00 Authoring application: mPDF 5.7
MD5: 8833d0413456b66687d5f839cfa8f6fe SHA-1: 75fc6f7e416630f33187a176d672aee6771a4607 SHA-256: d7d4ccf77bada7db86c9a11c5a2f355133cf2c97083c11aef92fd20b6a9b411f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a critical heuristic for containing a mass external link farm, with numerous URLs pointing to external PDF files. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the sheer volume of links suggests a distribution or SEO manipulation tactic. The primary IOCs are the external URLs hosted on duckdns.org.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.duckdns.org/9b21b24b28b22b26/I-Hope-You-Find-Me-The-Love-Poems-of-craigslist-s-Missed-Connections-by-Alan-Feuer.pdf
    • http://cmeinasaoo.duckdns.org/2b25b28b29b22b23/Missed-Connections-Love-Lost-amp-Found-by-Sophie-Blackall.pdf
    • http://cmeinasaoo.duckdns.org/8b20b26b28b24b28/Body-and-Soul-Connections-A-Book-of-Poems-by-Hassine-Saidane.pdf
    • http://cmeinasaoo.duckdns.org/3b23b26b29b26b20/Feuer---Gef-hrliche-Begierde-Feuer-3-by-Coreene-Callahan.pdf
    • http://cmeinasaoo.duckdns.org/1b20b29b27b20b21b28/Feuer-in-Der-Kultur-Feuer-Mythologie-Feuerbrauchtum-Feuerwerk-Kerze-Raucherwerk-Hephaistos-Salbei-Beifuss-Rosmarin-Vulcanus-Zi-by-Source-Wikipedia.pdf
    • http://cmeinasaoo.duckdns.org/2b25b28b28b20b27/For-the-Love-of-Jazz-by-Elke-Feuer.pdf
    • http://cmeinasaoo.duckdns.org/5b24b22b21b24b20/Love-Karma-Use-Your-Intuition-to-Find-Create-and-Nurture-Love-in-Your-Life-by-Char-Margolis.pdf
    • http://cmeinasaoo.duckdns.org/7b20b24b24b24b22/Find-Her-Keep-Her-A-Martha-s-Vineyard-Love-Story-Love-in-the-USA-1-by-Z-L-Arkadie.pdf
    • http://cmeinasaoo.duckdns.org/9b21b24b29b27b21/Crazy-in-Love---Gef-hrlich-sch-n-Connections-1-by-Kim-Karr.pdf
    • http://cmeinasaoo.duckdns.org/6b29b24b27b24b28/To-Find-A-Love-Like-Ours-by-Nikki-Walker.pdf
    • http://cmeinasaoo.duckdns.org/5b22b21b27b21/an-inkling-hope-select-poems-by-Erin-A-Thomas.pdf
    • http://cmeinasaoo.duckdns.org/5b28b27b21b20b22/War-amp-Love-Love-amp-War-New-and-Selected-Poems-New-and-Selected-Poems-by-Aharon-Shabtai.pdf
    • http://cmeinasaoo.duckdns.org/8b24b23b22/How-to-Find-Love-in-a-Bookshop-by-Veronica-Henry.pdf
    • http://cmeinasaoo.duckdns.org/3b24b25b22/How-to-Find-Love-in-a-Bookshop-by-Veronica-Henry.pdf
    • http://cmeinasaoo.duckdns.org/2b25b20b23b23b22/Craigslist-Lover-by-Ancelli.pdf
    • http://cmeinasaoo.duckdns.org/2b25b26b26b26/Let-Love-Find-You-Reid-Family-4-by-Johanna-Lindsey.pdf
    • http://cmeinasaoo.duckdns.org/8b23b28b20b26b27/Craigslist-Money-Making-Guide-for-Beginners-by-Bri.pdf
    • http://cmeinasaoo.duckdns.org/3b23b25b20b21b27/Attached-The-New-Science-of-Adult-Attachment-and-How-It-Can-Help-You-find-and-Keep-love-by-Amir-Levine.pdf
    • http://cmeinasaoo.duckdns.org/7b20b27b20b23b23/Easy-Craigslist-Money-Who-Else-Wants-to-Make-435-in-3-Hours-with-No-Investment-And-No-Experience-by-Gengis-Suarez.pdf
    • http://cmeinasaoo.duckdns.org/4b21b26b26b25b22/Scavenger-Scout-Rock-Hound-Seek-and-Find-Book-for-Kids-Who-Love-Rocks-by-Shelby-Wilde.pdf
    • http://cmeinasaoo.duckdns.org/7b20b24b24b24b22/Find-Her-Keep-Her-A-Martha-s-Vineyard-Love-Story-Lov