Malicious PDF — malware analysis report

Static analysis result for SHA-256 f060edc8551f7878…

MALICIOUS

PDF

21.6 KB Created: 2020-03-15 19:10:45 +00:00 Authoring application: mPDF 5.7
MD5: fd83864f23294b8f5093fb9dcb637cd7 SHA-1: c868abfe781f9cb945473f7ff880514c25baf410 SHA-256: f060edc8551f7878db24fd9c726615ce996c437a4bde3fd61a2ed9c667b0fa8e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links pointing to external PDFs hosted on the domain 'tanceubio.myhome.cx'. This is indicative of a link farm or a mechanism to distribute malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted, but the PDF structure itself is the primary vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/93d43d83d8/Turned-On-Science-Sex-and-Robots-by-Kate-Devlin.pdf
    • http://tanceubio.myhome.cx/13d03d13d13d53d23d7/Defining-the-Wind-The-Beaufort-Scale-and-How-a-19th-Century-Admiral-Turned-Science-Into-Poetry-by-Scott-Huler.pdf
    • http://tanceubio.myhome.cx/23d33d03d13d23d8/Just-Do-It-How-One-Couple-Turned-Off-the-TV-and-Turned-On-Their-Sex-Lives-for-101-Days-No-Excuses-by-Douglas-Brown.pdf
    • http://tanceubio.myhome.cx/13d63d73d23d13d8/Robots-From-Everyday-to-Out-of-This-World-by-YES-Mag.pdf
    • http://tanceubio.myhome.cx/23d53d93d53d63d5/GURPS-Reign-of-Steel-The-War-Is-Over-The-Robots-Won-by-David-L-Pulver.pdf
    • http://tanceubio.myhome.cx/83d43d93d03d03d4/War-Of-The-Robots-Doctor-Who-Decide-Your-Destiny-6-by-Trevor-Baxendale.pdf
    • http://tanceubio.myhome.cx/93d03d33d63d43d5/Zombies-Vs-Robots-A-Cyberpunk-Tale-of-Terror-by-Joe-Cautilli.pdf
    • http://tanceubio.myhome.cx/13d13d83d53d03d83d5/Making-Dinosaur-Robots-From-Junk-by-Stephen-Munzer.pdf
    • http://tanceubio.myhome.cx/73d43d53d43d23d2/Science-Projects-for-Kids-Making-Science-Fun-in-10-Minutes-or-Less-21-Science-Experiments-For-Kids-Ages-9---12-by-JoJo-Sabra.pdf
    • http://tanceubio.myhome.cx/33d83d43d43d93d6/The-Truth-About-Santa-Wormholes-Robots-and-What-Really-Happens-on-Christmas-Eve-by-Gregory-Mone.pdf
    • http://tanceubio.myhome.cx/53d13d63d83d43d6/Governing-Lethal-Behavior-in-Autonomous-Robots-by-Ronald-Arkin.pdf
    • http://tanceubio.myhome.cx/13d13d83d53d23d33d1/Robotz-An-Encyclopedia-Of-Robots-In-Fact-And-Fiction-by-Stephen-Munzer.pdf
    • http://tanceubio.myhome.cx/83d63d7/Rise-of-the-Robots-Technology-and-the-Threat-of-a-Jobless-Future-by-Martin-Ford.pdf
    • http://tanceubio.myhome.cx/13d13d93d53d23d33d7/The-Robots-are-Coming-A-Human-s-Survival-Guide-to-Profiting-in-the-Age-of-Automation-by-John-Pugliano.pdf
    • http://tanceubio.myhome.cx/33d53d53d33d6/The-Summer-I-Turned-Pretty-Trilogy-The-Summer-I-Turned-Pretty-It-s-Not-Summer-Without-You-We-ll-Always-Have-Summer-by-Jenny-Han.pdf
    • http://tanceubio.myhome.cx/43d93d93d23d03d0/GURPS-Robots-Bold-Experiments-Faithful-Servants-Soulless-Killers-by-David-L-Pulver.pdf
    • http://tanceubio.myhome.cx/83d43d13d33d1/Works-by-Kate-Chopin-Novels-by-Kate-Chopin-Short-Stories-by-Kate-Chopin-Desiree-s-Baby-the-Awakening-the-Storm-the-Story-of-an-Hour-by-Books-LLC.pdf
    • http://tanceubio.myhome.cx/23d93d53d23d93d2/All-of-Us-There-by-Polly-Devlin.pdf
    • http://tanceubio.myhome.cx/83d13d83d53d73d1/If-Not-Now-by-Denyse-Devlin.pdf
    • http://tanceubio.myhome.cx/43d93d53d73d13d6/Handy-Men-by-Delilah-Devlin.pdf
    • http://tanceubio.myhome.cx/13d13d83d53d03d83d5/Making-Dinosaur-Robots