Malicious PDF — malware analysis report

Static analysis result for SHA-256 002c49af8a9a85d5…

MALICIOUS

PDF

17.5 KB Created: 2020-03-11 22:49:30 +00:00 Authoring application: mPDF 5.7 First seen: 2021-07-13
MD5: 1a91ab9e1952183f44de678157dbde03 SHA-1: 5d8895251addf74318c5ae9b88a21cc888e91002 SHA-256: 002c49af8a9a85d5dec7bbe5d5955e7378265b0caefa589b0af4f61ee0dcd80f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains a large number of embedded URLs pointing to external PDF files, hosted on a domain associated with SEO link farming. The primary purpose appears to be directing users to these external resources, likely as part of a content-scraping or link-building scheme that has been flagged as malicious. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/1873872877879878/A-Long-Long-Sleep-by-Anna-Sheehan.pdf In PDF document text
    • http://kitasdyu.myhome.cx/5874876877879/Exodus-from-the-Long-Sun-The-Book-of-the-Long-Sun-4-by-Gene-Wolfe.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/2878874870870/Sancho-of-the-Long-Long-Horns-by-Allan-R-Bosworth.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/5874876877878/Lake-of-the-Long-Sun-The-Book-of-the-Long-Sun-2-by-Gene-Wolfe.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/3874873878/The-Long-Cosmos-The-Long-Earth-5-by-Terry-Pratchett.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1870872875870877/Litany-of-the-Long-Sun-The-Book-of-the-Long-Sun-1-2-by-Gene-Wolfe.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/5874876878871/Nightside-the-Long-Sun-The-Book-of-the-Long-Sun-1-by-Gene-Wolfe.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/3872879876875878/Pulled-Long-Long-Shots-3-by-Christine-d-39-Abo.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/9871874879874875/A-Long-Long-Way-To-The-Top-by-Laird-Tschonnie-Scribbler.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/4878873879877/The-Fundamentals-of-Long-Distance-Relationship-Things-You-Need-to-Know-About-Long-Distance-Relationships-LDR-and-Tips-How-to-Make-it-Work-by-Lisa-Daniel.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/7870873878877876/The-Justin-Long-Handbook---Everything-You-Need-to-Know-about-Justin-Long-by-Katie-Lessard.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/9877879875877875/Long-Long-Autumn-Nights-Selected-Poems-of-Oguma-Hideo-1901-1940-by-Hideo-Oguma.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/5876875879874/The-Long-Way-Long-Way-1-by-DomLuka.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1877875875873873/Daddy-Long-Legs-amp-Dear-Enemy-Daddy-Long-Legs-1-2-by-Jean-Webster.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1873876872874/A-Long-Way-from-Chicago-A-Long-Way-from-Chicago-1-by-Richard-Peck.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/3878874878873879/Long-Road-to-Baghdad-Long-Road-to-Baghdad-1-by-Catrin-Collier.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/3879879878879873/Good-Night-Sleep-Tight-The-Sleep-Lady-s-Gentle-Guide-to-Helping-Your-Child-Go-to-Sleep-Stay-Asleep-and-Wake-Up-Happy-by-Kim-West.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/9876874873870879/Herzfieber-T-r-an-T-r-mit-dir-by-Pia-Long.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/2879876876876/Long-Run-by-Nelson-C-Nye.pdfIn PDF document text
    • http://kitasdyu.myhome.cx/1879870870878879/Listening-by-Anne-Long.pdfIn PDF document text