Malicious PDF — malware analysis report

Static analysis result for SHA-256 d88b78468f076959…

MALICIOUS

PDF

19.2 KB Created: 2019-05-02 03:21:55 +01:00 Authoring application: mPDF 5.7
MD5: 20bf58c2668fb94a01b0bf352b8d8d0d SHA-1: 1c2f7f46a2ebaf49002469d876a9e97c861abc10 SHA-256: d88b78468f076959b25ae15de5bcad7810aa63f34ecd934bbd5ec824e1af3e4e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS classification indicate a malicious intent. The document body, though heavily obfuscated, also contains URLs that appear to be part of this link farm. The primary attack pattern involves directing users to external resources, potentially for SEO manipulation or to serve further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc.net/4c52c55c53c57c52/The-Tempted-Bride-An-Erotic-Cheating-Wife-Tale-by-Anne-Hedonia.pdf
    • http://zacdsa.linkpc.net/1c51c51c54c50c59c53/My-Wife-The-Hotwife-cuckold-chastity-cheating-wife-housewife-taboo-humiliation-size-queen-stretching-loving-wives-open-marriage-by-Ronnie-Kinski.pdf
    • http://zacdsa.linkpc.net/4c52c55c53c57c53/B-amp-D-Bridal-Shower-by-Anne-Hedonia.pdf
    • http://zacdsa.linkpc.net/4c52c55c53c57c56/A-Film-For-A-Few-Friends-by-Anne-Hedonia.pdf
    • http://zacdsa.linkpc.net/6c55c50c57c57c55/The-Right-Bride-Bride-of-Desire-The-English-Aristocrat-s-Bride-Vacancy-Wife-of-Convenience-by-Sara-Craven.pdf
    • http://zacdsa.linkpc.net/1c50c50c58c54c59c54/Kirstie-s-Tale---The-Box-Set-A-Tale-of-BDSM-Erotic-Romance-by-Simone-Leigh.pdf
    • http://zacdsa.linkpc.net/4c55c59c53c59c55/Sister-Wife-An-erotic-Novelette-by-Paige-Aspen.pdf
    • http://zacdsa.linkpc.net/1c51c51c54c52c57c56/The-Well-Endowed-Stud-No-Cuckold-Can-Stop-Him-No-Hotwife-Can-Resist-Him-a-sizzling-tale-of-cheating-betrayal-and-adultery-by-a-neighbor-with-an-enormous-massive-secret-by-Ronnie-Kinski.pdf
    • http://zacdsa.linkpc.net/4c57c58c59c58c56/Taken-by-the-Monsters-An-Erotic-Monster-Tale-by-K-J-Burkhardt.pdf
    • http://zacdsa.linkpc.net/2c58c58c55c54c54/The-Anniversary-An-Erotic-Tale-by-Crow-Gray.pdf
    • http://zacdsa.linkpc.net/7c54c57c50c59c54/The-Gargoyle-An-Erotic-Tale-by-Reveille-Richards.pdf
    • http://zacdsa.linkpc.net/4c53c51c57c58c50/The-Tale-Of-The-Vampire-Bride-Vampire-Bride-1-by-Rhiannon-Frater.pdf
    • http://zacdsa.linkpc.net/1c57c51c50c50c53/One-Night-with-the-Brother-In-Law-An-Erotic-Tale-by-Emma-Barnes.pdf
    • http://zacdsa.linkpc.net/1c50c59c57c50c59c50/Committed-An-Erotic-Valentine-s-Tale-by-Lissa-Matthews.pdf
    • http://zacdsa.linkpc.net/3c50c54c56c58c51/Welcome-to-the-Fish-Tank-An-Erotic-Fairy-Tale-by-Big-Kahuna.pdf
    • http://zacdsa.linkpc.net/1c52c53c55c58c54/Little-Red-and-the-Big-Bad-Wolf-A-BBW-Paranormal-Erotic-Fairy-Tale-by-Ellen-Dominick.pdf
    • http://zacdsa.linkpc.net/8c54c54c54c54c51/Cinder-An-Erotic-Modern-Fairy-Tale-by-Victoria-Brice.pdf
    • http://zacdsa.linkpc.net/1c58c58c57c58c53/The-Mystic-Mirror-Erotic-Fairy-Tale-Romance-by-Sandra-Ross.pdf
    • http://zacdsa.linkpc.net/1c54c58c55c52c54/The-Book-Of-Twenty-Four-A-Seth-amp-Amber-Erotic-Tale-1-by-Nathan-L-Flamank.pdf
    • http://zacdsa.linkpc.net/2c50c53c52c58c53/Captive-in-the-Spotlight-Blackmailed-Bride-Innocent-Wife-by-Annie-West.pdf