Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d335c61d91357db…

MALICIOUS

PDF

20.3 KB Created: 2020-03-14 00:54:39 +00:00 Authoring application: mPDF 5.7
MD5: 3e677b4a93be4fee04ca155567049555 SHA-1: ef7de8f5caf2ee63d8c93d0b56b91a999939be3d SHA-256: 0d335c61d91357db938bf913bc4cf2a17e71b24e1c3e1f6d38e21f9fc17e564f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files, hosted on a domain with a suspicious structure. This suggests a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious, reinforcing the suspicious nature of the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/2557553551555556/Barulho-Uma-viagem-pelo-underground-do-Rock-Americano-by-Andr-Barcinski.pdf
    • http://ieuicufioao.myhome.cx/4559558550559557/Rock-Me-Tonight-Underground-Encounters-3-by-Lisa-Carlisle.pdf
    • http://ieuicufioao.myhome.cx/4559558552554555/Ripped-T-Shirts-from-the-Underground-Indie-Rock-T-Shirts-from-the-1970s-to-the-1990s-by-Cesar-Padilla.pdf
    • http://ieuicufioao.myhome.cx/4553557554552557/Americano-Abroad-A-Year-of-Travel-in-Stories-by-Dominic-Carrillo.pdf
    • http://ieuicufioao.myhome.cx/5550554551558558/Rethinking-Early-Childhood-Education-by-Ann-Pelo.pdf
    • http://ieuicufioao.myhome.cx/6555555556556557/People-from-Libreville-Jean-Eyegh-Ndong-Daniel-Cousin-Jean-Franois-Ntoutoume-Emane-Andr-Dieudonn-Berre-Catilina-Aubameyang-by-Books-LLC.pdf
    • http://ieuicufioao.myhome.cx/2556556552551553/The-Language-of-Art-Inquiry-Based-Studio-Practices-in-Early-Childhood-Settings-by-Ann-Pelo.pdf
    • http://ieuicufioao.myhome.cx/9552552553552558/N-o-Espere-pelo-Amanh-dio-e-amor-nunca-foram-t-o-pr-ximos-by-Josy-Stoque.pdf
    • http://ieuicufioao.myhome.cx/3558553557553557/A-ltima-Viagem-do-Lusitania-by-Erik-Larson.pdf
    • http://ieuicufioao.myhome.cx/2554551552551550/Viagem-Roda-do-Meu-Nome-by-Alice-Vieira.pdf
    • http://ieuicufioao.myhome.cx/4551552554555551/Viagem-a-Praga-no-Tempo-da-Ditadura-by-Dulce-Rodrigues.pdf
    • http://ieuicufioao.myhome.cx/8553555559553556/Os-Confins-da-Terra-Uma-Viagem-na-V-spera-do-S-culo-21-by-Robert-D-Kaplan.pdf
    • http://ieuicufioao.myhome.cx/9557559551555556/Jarda-Ap-s-Jarda-A-hist-ria-do-futebol-americano-na-televis-o-brasileira-by-Andr-L-Magalh-es.pdf
    • http://ieuicufioao.myhome.cx/2557555557556550/Rock-Your-Plot-A-Simple-System-for-Plotting-Your-Novel-Rock-Your-Writing-1-by-Cathy-Yardley.pdf
    • http://ieuicufioao.myhome.cx/2557556554550551/The-Prince-of-Punk-Rock-Radical-Rock-Stars-1-by-Jenna-Galicki.pdf
    • http://ieuicufioao.myhome.cx/8550554559559551/It-s-not-only-rock-n-roll-Sexe-drogues-et-sagesse-du-rock-by-Catherine-Viale.pdf
    • http://ieuicufioao.myhome.cx/4559558552550557/Rock-of-Ages-The-Rolling-Stone-History-of-Rock-and-Roll-by-Ed-Ward.pdf
    • http://ieuicufioao.myhome.cx/3551550550555558/Between-A-Rock-and-A-Hard-Place-Radical-Rock-Stars-2-by-Jenna-Galicki.pdf
    • http://ieuicufioao.myhome.cx/1551553557554553552/The-Rock-Star-s-Secret-Baby-Rock-Stars-in-Disguise-Book-5-Cadell-by-Blair-Babylon.pdf
    • http://ieuicufioao.myhome.cx/9557559557557555/Rock-Deadly-The-Rock-and-Roll-Mysteries-1-by-Kathryn-Lively.pdf