Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d45aa4c430d509c…

MALICIOUS

PDF

20.0 KB Created: 2020-03-05 10:25:10 +00:00 Authoring application: mPDF 5.7
MD5: a99038d0a45b74a3287f9b49d0909fab SHA-1: dc6863c33a4f9c64bdcd890ef47218c9360db78a SHA-256: 0d45aa4c430d509cd78dc1badc31b7e86cb0d6534e5315241826a53ab5f7fe98
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by multiple heuristics, including a critical finding for a link farm containing 26 external URLs. The ML classifier also strongly indicated maliciousness. The embedded URLs, such as http://tanceubio.myhome.cx/23d43d93d93d03d2/Drawn-From-Paradise-The-Discovery-Art-and-Natural-History-of-the-Birds-of-Paradise-by-David-Attenborough.pdf, are likely used to direct users to malicious content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/23d43d93d93d03d2/Drawn-From-Paradise-The-Discovery-Art-and-Natural-History-of-the-Birds-of-Paradise-by-David-Attenborough.pdf
    • http://tanceubio.myhome.cx/23d23d13d73d03d6/Birds-of-Paradise-by-Diana-Abu-Jaber.pdf
    • http://tanceubio.myhome.cx/23d23d63d23d23d7/Birds-of-a-Lesser-Paradise-Stories-by-Megan-Mayhew-Bergman.pdf
    • http://tanceubio.myhome.cx/83d23d43d83d73d8/F-Scott-Fitzgerald-Four-Pack---Benjamin-Button-This-Side-of-Paradise-The-Beautiful-and-Damned-The-Diamond-as-big-as-The-Ritz-Illustrated-by-Norman-Rockwell-by-F-Scott-Fitzgerald.pdf
    • http://tanceubio.myhome.cx/23d83d63d53d33d9/Paradise-Series-Paradise-Series-1-2-3-Crazy-in-Paradise-Deception-in-Paradise-Trouble-in-Paradise-Box-Set-by-Deborah-Brown.pdf
    • http://tanceubio.myhome.cx/23d13d03d53d33d8/Pretty-Birds-by-Scott-Simon.pdf
    • http://tanceubio.myhome.cx/63d63d63d13d03d2/Paul-Gauguin-The-Search-For-Paradise-Letters-From-Brittany-And-The-South-Seas-by-Paul-Gauguin.pdf
    • http://tanceubio.myhome.cx/33d93d73d53d23d8/For-the-Birds-by-Aaron-Paul-Lazar.pdf
    • http://tanceubio.myhome.cx/23d33d53d13d5/Living-on-the-Wind-Across-the-Hemisphere-with-Migratory-Birds-by-Scott-Weidensaul.pdf
    • http://tanceubio.myhome.cx/93d93d83d63d43d1/The-Side-of-Paradise-by-F-Scott-Fitzgerald.pdf
    • http://tanceubio.myhome.cx/93d93d83d33d13d1/This-Side-of-Paradise-by-F-Scott-Fitzgerald.pdf
    • http://tanceubio.myhome.cx/23d43d63d13d13d6/Good-Vibrations-Welcome-to-Paradise-1-by-S-L-Scott.pdf
    • http://tanceubio.myhome.cx/13d13d23d23d73d43d9/Good-Sensations-Welcome-to-Paradise-3-by-S-L-Scott.pdf
    • http://tanceubio.myhome.cx/13d03d73d43d93d8/Soldiers-of-Paradise-The-Starbridge-Chronicles-1-by-Paul-Park.pdf
    • http://tanceubio.myhome.cx/43d23d83d33d93d8/Soldiers-of-Paradise-The-Starbridge-Chronicles-1-by-Paul-Park.pdf
    • http://tanceubio.myhome.cx/93d73d73d03d53d7/Birder-s-Handbook-A-Field-Guide-to-the-Natural-History-of-North-American-Birds-by-Paul-R-Ehrlich.pdf
    • http://tanceubio.myhome.cx/43d93d43d63d33d5/Birds-of-the-Tideline-Shore-Birds-of-the-Northern-Hemisphere-by-Alan-Richards.pdf
    • http://tanceubio.myhome.cx/63d83d33d03d63d2/About-Indian-Birds-Including-Birds-of-Nepal-Sri-Lanka-Bhutan-Pakistan-amp-Bangladesh-by-S-lim-Ali.pdf
    • http://tanceubio.myhome.cx/33d63d73d53d23d7/Consider-the-Birds-A-Provocative-Guide-to-the-Birds-of-the-Bible-by-Debbie-Blue.pdf
    • http://tanceubio.myhome.cx/43d83d93d43d23d4/The-Day-of-the-Scorpion-by-Paul-Scott.pdf