Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef9819157c3cf3a8…

MALICIOUS

PDF

20.5 KB Created: 2020-03-16 18:26:18 +00:00 Authoring application: mPDF 5.7
MD5: c7611602f16e6cccb41ad95f304d9d3d SHA-1: 49f3747d7c35cf977ea366fefd60ab3581faae68 SHA-256: ef9819157c3cf3a87ee583f688938c131721530d81afff4435fb005037cb081e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents on the domain 'tanceubio.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/13d03d73d43d93d8/Soldiers-of-Paradise-The-Starbridge-Chronicles-1-by-Paul-Park.pdf
    • http://tanceubio.myhome.cx/43d23d83d33d93d8/Soldiers-of-Paradise-The-Starbridge-Chronicles-1-by-Paul-Park.pdf
    • http://tanceubio.myhome.cx/13d53d73d63d23d4/Paradise-Park-by-Allegra-Goodman.pdf
    • http://tanceubio.myhome.cx/23d83d63d53d33d9/Paradise-Series-Paradise-Series-1-2-3-Crazy-in-Paradise-Deception-in-Paradise-Trouble-in-Paradise-Box-Set-by-Deborah-Brown.pdf
    • http://tanceubio.myhome.cx/63d63d63d13d03d2/Paul-Gauguin-The-Search-For-Paradise-Letters-From-Brittany-And-The-South-Seas-by-Paul-Gauguin.pdf
    • http://tanceubio.myhome.cx/13d13d63d23d93d63d0/Jurassic-Park-Michael-Crichton-List-of-Jurassic-Park-Characters-the-Lost-World-Jurassic-Park-Jurassic-Park-III-Biological-Issue-by-Source-Wikipedia.pdf
    • http://tanceubio.myhome.cx/13d63d83d63d73d2/The-Birds-of-Paradise-by-Paul-Scott.pdf
    • http://tanceubio.myhome.cx/83d13d13d83d6/Rucker-Park-Setup-by-Paul-Volponi.pdf
    • http://tanceubio.myhome.cx/13d23d63d33d73d3/The-Hidden-World-Princess-of-Roumania-4-by-Paul-Park.pdf
    • http://tanceubio.myhome.cx/13d83d63d33d53d1/Sunset-Park-Paul-Auster-by-Paul-Auster.pdf
    • http://tanceubio.myhome.cx/63d83d13d83d8/Beyond-the-Deepwoods-The-Edge-Chronicles-The-Twig-Saga-1-The-Edge-Chronicles-4-by-Paul-Stewart.pdf
    • http://tanceubio.myhome.cx/13d63d33d73d33d8/Silent-Dances-Starbridge-2-by-A-C-Crispin.pdf
    • http://tanceubio.myhome.cx/43d23d53d23d33d3/Ancestor-s-World-Starbridge-6-by-A-C-Crispin.pdf
    • http://tanceubio.myhome.cx/33d33d03d23d23d4/Mystical-Paths-Starbridge-5-by-Susan-Howatch.pdf
    • http://tanceubio.myhome.cx/23d43d93d93d03d2/Drawn-From-Paradise-The-Discovery-Art-and-Natural-History-of-the-Birds-of-Paradise-by-David-Attenborough.pdf
    • http://tanceubio.myhome.cx/73d03d03d23d23d9/Paradise-Lost-Paradise-Regained-Samson-Agonistes-by-John-Milton.pdf
    • http://tanceubio.myhome.cx/83d33d13d63d33d4/Puppies-in-Paradise-Tj-Jensen-Paradise-Lake-Mystery-5-by-Kathi-Daley.pdf
    • http://tanceubio.myhome.cx/43d83d93d03d43d5/Pumpkins-in-Paradise-Tj-Jensen-Paradise-Lake-Mystery-1-by-Kathi-Daley.pdf
    • http://tanceubio.myhome.cx/13d13d73d63d43d83d3/Moderne-Im-Park-Der-Architekt-Helmut-Riemann-Und-Die-H-user-Im-Reemtsma-Park-In-Hamburg-by-Ulrich-H-hns.pdf
    • http://tanceubio.myhome.cx/23d53d33d33d9/Return-to-Paradise-Leaving-Paradise-2-by-Simone-Elkeles.pdf
    • http://tanceubio.myhome.cx/13d13d63d23d93d63d0/Jurassic-Park-Michael-Crichton-List-of-Jurassic-