Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4724ad89575a0a1…

MALICIOUS

PDF

20.3 KB Created: 2020-03-19 22:39:53 +00:00 Authoring application: mPDF 5.7
MD5: 531c93c626242b4180dfe77e310141a0 SHA-1: efd5c1591fb2db48aa39297471c0c18463764fec SHA-256: e4724ad89575a0a1492999baf4f8171c668110a441516468c6fe93d8bbe12101
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. The embedded URLs are likely used to redirect the user to malicious content or to facilitate a phishing attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/46a76a06a46a9/The-Quilter-s-Apprentice-Elm-Creek-Quilts-1-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/66a76a76a26a86a5/The-Quilter-s-Kitchen-Elm-Creek-Quilts-13-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/36a56a76a46a96a7/The-Master-Quilter-Elm-Creek-Quilts-6-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/36a56a76a36a36a5/A-Quilter-s-Holiday-Elm-Creek-Quilts-15-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/66a76a76a26a26a0/The-Quilter-s-Homecoming-Elm-Creek-Quilts-10-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/66a76a76a26a86a7/ELM-Creek-Quilts-Quilt-Projects-Inspired-by-the-ELM-Creek-Quilts-Novels-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/66a76a76a36a16a9/Return-to-Elm-Creek-More-Quilt-Projects-Inspired-by-the-Elm-Creek-Quilts-Novels-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/36a86a46a56a16a4/The-Christmas-Quilt-Elm-Creek-Quilts-8-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/66a76a76a26a16a9/Circle-of-Quilters-Elm-Creek-Quilts-9-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/66a76a76a26a86a3/The-Giving-Quilt-Elm-Creek-Quilts-20-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/36a56a76a46a96a3/The-Winding-Ways-Quilt-Elm-Creek-Quilts-12-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/86a36a86a16a8/The-Sugar-Camp-Quilt-Elm-Creek-Quilts-7-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/36a56a86a26a26a0/Christmas-Bells-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/16a16a76a66a96a16a0/Fates-and-Traitors-A-Novel-of-John-Wilkes-Booth-by-Jennifer-Chiaverini.pdf
    • http://rtuninnsi.myhome.cx/36a26a66a66a56a3/The-Last-Apprentice-Slither-The-Last-Apprentice-Wardstone-Chronicles-11-by-Joseph-Delaney.pdf
    • http://rtuninnsi.myhome.cx/56a56a06a26a1/The-Spook-s-Apprentice-The-Last-Apprentice-Wardstone-Chronicles-1-by-Joseph-Delaney.pdf
    • http://rtuninnsi.myhome.cx/16a06a46a76a86a76a8/The-Ninja-Apprentice-The-Lost-Scrolls-of-Fudo-Shin-The-Ninja-Apprentice-1-by-Jon-F-Merz.pdf
    • http://rtuninnsi.myhome.cx/76a86a66a26a46a1/Paydunor-An-Apprentice-Eternal-An-Apprentice-Eternal-by-Brad-Allen-Deborde.pdf
    • http://rtuninnsi.myhome.cx/16a86a86a66a26a2/Maddie-s-Quilt-The-Quilter-s-Son-4-by-Samantha-Bayarr.pdf
    • http://rtuninnsi.myhome.cx/36a76a36a96a96a4/Christmas-on-Main-Street-Snowberry-Creek-1-5-Shelter-Bay-6-5-Cricket-Creek-5-5-Bayberry-Island-0-5-by-JoAnn-Ross.pdf