Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9e67f5dc5a8c582…

MALICIOUS

PDF

19.9 KB Created: 2020-03-15 21:04:48 +00:00 Authoring application: mPDF 5.7
MD5: 177b8c2d34e946cd5db60ec6959f82ec SHA-1: 579998af21d8cec2698eaf92ca97baed7b951f96 SHA-256: e9e67f5dc5a8c5821740298cfc634f275495ceb96e5759621b16bb8c6a408254
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'rtuninnsi.myhome.cx'. This behavior is indicative of SEO poisoning or a link farm, designed to drive traffic to malicious or low-quality content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/36a46a46a56a86a8/Hollywood-Scandals-Hollywood-Headlines-1-by-Gemma-Halliday.pdf
    • http://rtuninnsi.myhome.cx/16a16a76a16a36a76a6/Hollywood-Headlines-Mysteries-Boxed-Set-Hollywood-Headlines-1-3-by-Gemma-Halliday.pdf
    • http://rtuninnsi.myhome.cx/36a46a46a56a86a6/Hollywood-Secrets-Hollywood-Headlines-2-by-Gemma-Halliday.pdf
    • http://rtuninnsi.myhome.cx/16a06a06a96a36a36a6/Vier-Schnappsch-sse-und-ein-Todesfall-Hollywood-Gossip-2-by-Gemma-Halliday.pdf
    • http://rtuninnsi.myhome.cx/16a16a06a96a06a56a9/Citizen-Hollywood-A-Novel-of-Golden-Era-Hollywood-Hollywood-s-Garden-of-Allah-3-by-Martin-Turnbull.pdf
    • http://rtuninnsi.myhome.cx/26a66a56a26a96a5/Hollywood-Secrets-and-Scandals-by-Sue-Cameron.pdf
    • http://rtuninnsi.myhome.cx/36a56a16a86a96a3/Scandals-of-Classic-Hollywood-Sex-Deviance-and-Drama-from-the-Golden-Age-of-American-Cinema-by-Anne-Helen-Petersen.pdf
    • http://rtuninnsi.myhome.cx/16a16a06a86a86a96a8/The-Trouble-with-Scarlett-A-Novel-of-Golden-Era-Hollywood-Hollywood-s-Garden-of-Allah-2-by-Martin-Turnbull.pdf
    • http://rtuninnsi.myhome.cx/56a46a06a26a46a5/The-Case-of-the-Hollywood-Art-Heist-The-North-Hollywood-Detective-Club-1-by-Mike-Mains.pdf
    • http://rtuninnsi.myhome.cx/66a46a06a76a1/Hollywood-Wives-Hollywood-Series-1-by-Jackie-Collins.pdf
    • http://rtuninnsi.myhome.cx/16a16a06a86a76a46a5/The-Garden-on-Sunset-A-Novel-of-Golden-Era-Hollywood-Hollywood-s-Garden-of-Allah-1-by-Martin-Turnbull.pdf
    • http://rtuninnsi.myhome.cx/16a76a26a76a66a5/Hollywood-Station-Hollywood-Station-1-by-Joseph-Wambaugh.pdf
    • http://rtuninnsi.myhome.cx/66a26a26a46a66a4/Les-Plaisirs-d-Hollywood---1-Les-plaisirs-d-Hollywood-by-Lauren-Conrad.pdf
    • http://rtuninnsi.myhome.cx/16a96a76a76a56a3/Viva-Las-Vegas-by-Gemma-Halliday.pdf
    • http://rtuninnsi.myhome.cx/56a16a56a86a96a3/Confessions-of-a-Bombshell-Bandit-by-Gemma-Halliday.pdf
    • http://rtuninnsi.myhome.cx/36a16a46a66a26a4/Hollywood-Lies-by-N-K-Smith.pdf
    • http://rtuninnsi.myhome.cx/46a26a66a06a16a8/Sinatra-in-Hollywood-by-Tom-Santopietro.pdf
    • http://rtuninnsi.myhome.cx/46a36a36a26a66a8/Eve-in-Hollywood-by-Amor-Towles.pdf
    • http://rtuninnsi.myhome.cx/36a16a46a36a46a6/Hollywood-by-Gore-Vidal.pdf
    • http://rtuninnsi.myhome.cx/66a66a46a86a36a2/Mislaid-In-Hollywood-by-Joe-Hyams.pdf