Malicious PDF — malware analysis report

Static analysis result for SHA-256 122052bdafe63691…

MALICIOUS

PDF

26.0 KB Created: 2020-03-16 18:22:26 +00:00 Authoring application: mPDF 5.7
MD5: bd1a0a46feb247ca781d0ef13b1828ba SHA-1: b397e11d907bf664b3804494c9149600141950a7 SHA-256: 122052bdafe63691236b130d0110e9e89cb0cdbee39083db767d2a833e6ca15f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier as malicious and contains a large number of embedded links. These links point to external PDF files hosted on the domain 'tanceubio.myhome.cx', suggesting a link farm or a distribution mechanism for further malicious content. While no scripts were explicitly extracted, the presence of embedded links within a PDF is a common technique for initial access via spearphishing attachments.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/23d33d53d13d5/Living-on-the-Wind-Across-the-Hemisphere-with-Migratory-Birds-by-Scott-Weidensaul.pdf
    • http://tanceubio.myhome.cx/43d93d43d63d33d5/Birds-of-the-Tideline-Shore-Birds-of-the-Northern-Hemisphere-by-Alan-Richards.pdf
    • http://tanceubio.myhome.cx/13d63d83d63d73d2/The-Birds-of-Paradise-by-Paul-Scott.pdf
    • http://tanceubio.myhome.cx/23d13d03d53d33d8/Pretty-Birds-by-Scott-Simon.pdf
    • http://tanceubio.myhome.cx/83d93d43d63d43d7/Minus-31-amp-the-Wind-Blowing-9-Reflections-about-Living-on-Land-by-John-Meade-Haines.pdf
    • http://tanceubio.myhome.cx/13d73d73d83d63d3/Mating-Rituals-of-Migratory-Humans-A-Novel-of-Sex-Restaurants-and-Redemption-by-Jason-R-Richter.pdf
    • http://tanceubio.myhome.cx/13d43d13d23d23d5/Living-Dead-Girl-by-Elizabeth-Scott.pdf
    • http://tanceubio.myhome.cx/13d13d33d83d13d23d4/Living-the-Good-Death-by-Scott-Baron.pdf
    • http://tanceubio.myhome.cx/13d03d13d13d53d23d7/Defining-the-Wind-The-Beaufort-Scale-and-How-a-19th-Century-Admiral-Turned-Science-Into-Poetry-by-Scott-Huler.pdf
    • http://tanceubio.myhome.cx/63d83d33d03d63d2/About-Indian-Birds-Including-Birds-of-Nepal-Sri-Lanka-Bhutan-Pakistan-amp-Bangladesh-by-S-lim-Ali.pdf
    • http://tanceubio.myhome.cx/33d23d03d63d03d4/Never-Leave-Your-Block-Adventures-in-Urban-Living-by-Scott-Jacobs.pdf
    • http://tanceubio.myhome.cx/33d43d03d73d23d9/Toolbox-for-Sustainable-City-Living-A-Do-It-Ourselves-Guide-by-Scott-Kellogg.pdf
    • http://tanceubio.myhome.cx/33d63d73d53d23d7/Consider-the-Birds-A-Provocative-Guide-to-the-Birds-of-the-Bible-by-Debbie-Blue.pdf
    • http://tanceubio.myhome.cx/53d63d83d63d73d6/Zeldapedia---The-Legend-of-Zelda-The-Wind-Waker-Characters-Abe-Aldo-Ankle-Anton-the-Wind-Waker-Aryll-Baito-Basht-and-Bisht-Beedle-Candy-the-Wind-Waker-Cannon-Character-Carlov-Cupid-Cyclos-Dampa-Daphnes-Nohansen-Hyrule-David-Jr-by-Source-Wikia.pdf
    • http://tanceubio.myhome.cx/13d73d23d43d23d5/The-Wind-Singer-Wind-on-Fire-1-by-William-Nicholson.pdf
    • http://tanceubio.myhome.cx/43d93d63d93d7/East-Wind-West-Wind-by-Pearl-S-Buck.pdf
    • http://tanceubio.myhome.cx/23d83d53d63d43d9/Fire-Wind-The-Wind-Drifters-1-by-Guy-S-Stanton-III.pdf
    • http://tanceubio.myhome.cx/73d93d83d73d13d8/Fauna-of-Mozambique-Birds-of-Mozambique-Mammals-of-Mozambique-Reptiles-of-Mozambique-Coelacanth-List-of-Birds-of-Mozambique-by-Source-Wikipedia.pdf
    • http://tanceubio.myhome.cx/63d53d63d33d33d8/The-situation-in-El-Salvador-hearings-before-the-Subcommittees-on-Human-Rights-and-International-Organizations-and-on-Western-Hemisphere-Affairs-of-Ninety-eighth-Congress-second-session-Janua-by-United-States-Congress-House-Committe.pdf
    • http://tanceubio.myhome.cx/33d53d43d53d93d8/The-Good-Life-Helen-and-Scott-Nearing-s-Sixty-Years-of-Self-Sufficient-Living-by-Helen-Nearing.pdf