Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d820cfbbdc19dde…

MALICIOUS

PDF

21.2 KB Created: 2020-03-12 02:19:25 +00:00 Authoring application: mPDF 5.7
MD5: 07578d1faa42385786c5689ea12fa0a7 SHA-1: 2f2fe9f197c02b7a3fbb650775febe385ffd709b SHA-256: 0d820cfbbdc19dde54143f8a11689a21e9c66a322ef3268c60369cc4303365a1
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains a large number of embedded links to external PDF files, masquerading as historical texts. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm, suggesting a tactic to drive traffic or distribute further malicious content. The ML classifier also flagged this document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tikytsesapdf.myhome.cx/378c678c878c778c978c7/Alexander-Hamilton-American-by-Richard-Brookhiser.pdf
    • http://tikytsesapdf.myhome.cx/178c678c178c778c2/Alexander-Hamilton-in-the-American-Tradition-by-Louis-Morton-Hacker.pdf
    • http://tikytsesapdf.myhome.cx/378c778c178c678c578c7/What-Would-the-Founders-Do-Our-Questions-Their-Answers-by-Richard-Brookhiser.pdf
    • http://tikytsesapdf.myhome.cx/278c278c978c778c878c3/George-Washington-on-Leadership-by-Richard-Brookhiser.pdf
    • http://tikytsesapdf.myhome.cx/778c578c478c678c878c4/Founding-Father-Rediscovering-George-Washington-by-Richard-Brookhiser.pdf
    • http://tikytsesapdf.myhome.cx/478c278c178c578c078c8/The-Federalist-Papers-by-Alexander-Hamilton.pdf
    • http://tikytsesapdf.myhome.cx/778c878c578c478c978c8/Federalist-Papers-by-Alexander-Hamilton.pdf
    • http://tikytsesapdf.myhome.cx/178c978c478c878c578c5/Alexander-Hamilton-A-Biography-by-Forrest-McDonald.pdf
    • http://tikytsesapdf.myhome.cx/478c678c278c678c678c7/Alexander-Hamilton-the-Outsider-by-Jean-Fritz.pdf
    • http://tikytsesapdf.myhome.cx/378c678c878c478c978c5/Duel-Alexander-Hamilton-Aaron-Burr-and-the-Future-of-America-by-Thomas-J-Fleming.pdf
    • http://tikytsesapdf.myhome.cx/978c478c778c978c878c0/American-Dreams-American-Realities-An-Introduction-to-the-Uses-of-History-by-Richard-C-Frucht.pdf
    • http://tikytsesapdf.myhome.cx/678c878c478c978c178c1/Thomas-Jefferson-Versus-Alexander-Hamilton-Confrontations-that-Shaped-a-Nation-by-Noble-E-Cunningham-Jr-.pdf
    • http://tikytsesapdf.myhome.cx/378c678c978c578c678c3/Hamilton-An-American-Biography-by-Tony--Williams.pdf
    • http://tikytsesapdf.myhome.cx/578c078c578c378c478c5/The-Adventure-Begins-by-Richard-Ashley-Hamilton.pdf
    • http://tikytsesapdf.myhome.cx/878c578c078c778c178c8/Richard-Hamilton-The-Unknown-Masterpiece-by-Christopher-Riopelle.pdf
    • http://tikytsesapdf.myhome.cx/378c878c278c678c578c3/The-Bone-Pedlar-Sir-Richard-Straccan-1-by-Sylvian-Hamilton.pdf
    • http://tikytsesapdf.myhome.cx/478c478c778c278c078c2/Duel-with-the-Devil-The-True-Story-of-How-Alexander-Hamilton-and-Aaron-Burr-Teamed-Up-to-Take-on-America-s-First-Sensational-Murder-Mystery-by-Paul-Collins.pdf
    • http://tikytsesapdf.myhome.cx/278c578c778c278c578c1/Hamilton-s-Curse-How-Jefferson-s-Arch-Enemy-Betrayed-the-American-Revolution--and-What-It-Means-for-Americans-Today-by-Thomas-J-DiLorenzo.pdf
    • http://tikytsesapdf.myhome.cx/778c078c478c178c478c8/American-Public-School-Law-by-Kern-Alexander.pdf
    • http://tikytsesapdf.myhome.cx/778c678c378c378c1/With-All-Despatch-Richard-Bolitho-10-by-Alexander-Kent.pdf