Malicious PDF — malware analysis report

Static analysis result for SHA-256 157439913a988be9…

MALICIOUS

PDF

19.4 KB Created: 2020-03-20 11:47:38 +00:00 Authoring application: mPDF 5.7
MD5: 102ab98b9b5885fa6bf1af15a6180c45 SHA-1: 51822f7ce0a7093cc3f6da77034b56c25249d416 SHA-256: 157439913a988be9267ef73766763358b76afb693f7bb87cbb6f6571412ef05e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm, which is a common technique for distributing malware or directing users to phishing sites. The ML classifier also flagged this PDF as malicious. The embedded URLs are likely used to download a second-stage payload or redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9519

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1558555559558550/Keeping-the-Dream-Alive-The-Cases-and-Causes-of-the-Southern-Poverty-Law-Center-by-Southern-Poverty-Law-Center.pdf
    • http://ieuicufioao.myhome.cx/4554556557559555/Why-Global-Poverty-A-Companion-Guide-to-the-Film-the-End-of-Poverty-by-Clifford-W-Cobb.pdf
    • http://ieuicufioao.myhome.cx/1553557555559551/Op-Center-Tom-Clancy-s-Op-Center-1-by-Jeff-Rovin.pdf
    • http://ieuicufioao.myhome.cx/2559553550558559/The-Center-Circle-Book-1-in-The-Center-Circle-Chronicles-by-Steve-Biddison.pdf
    • http://ieuicufioao.myhome.cx/4553554559558559/Southern-Spirits-Southern-Ghost-Hunter-Mysteries-1-by-Angie-Fox.pdf
    • http://ieuicufioao.myhome.cx/2556550551557/Area-X-The-Southern-Reach-Trilogy-Southern-Reach-1-3-by-Jeff-VanderMeer.pdf
    • http://ieuicufioao.myhome.cx/3550557558553553/The-Best-of-Southern-Living-Cookbook-Over-500-of-Our-All-Time-Favorite-Recipes-by-Southern-Living-Inc-.pdf
    • http://ieuicufioao.myhome.cx/1550557558559554558/Southern-Living-1989-Annual-Recipes-by-Southern-Living-Inc-.pdf
    • http://ieuicufioao.myhome.cx/3550557558551554/The-All-New-Ultimate-Southern-Living-Cookbook-Over-1-250-of-Our-Best-Recipes-by-Southern-Living-Inc-.pdf
    • http://ieuicufioao.myhome.cx/1554552558552559/Prisons-of-Poverty-by-Lo-c-Wacquant.pdf
    • http://ieuicufioao.myhome.cx/3556551550559557/A-Poverty-of-Words-by-Frederick-Pollack.pdf
    • http://ieuicufioao.myhome.cx/1558555559559551/Escaping-Poverty-by-Reading-Harbor.pdf
    • http://ieuicufioao.myhome.cx/3559555558552556/The-Poverty-of-Philosophy-by-Karl-Marx.pdf
    • http://ieuicufioao.myhome.cx/4550554556555558/See-Poverty-Be-The-Difference-by-Donna-Beegle.pdf
    • http://ieuicufioao.myhome.cx/3559556551550550/The-Poverty-of-Historicism-by-Karl-Popper.pdf
    • http://ieuicufioao.myhome.cx/1559553554552553/Street-Angel-The-Princess-of-Poverty-by-Jim-Rugg.pdf
    • http://ieuicufioao.myhome.cx/4558559557553552/Southern-Fried-Sushi-Southern-Fried-Sushi-1-by-Jennifer-Rogers-Spinola.pdf
    • http://ieuicufioao.myhome.cx/8553557557550556/Poverty-War-and-Violence-in-South-Africa-by-Clifton-C-Crais.pdf
    • http://ieuicufioao.myhome.cx/2552558559551550/Love-Poverty-and-War-Journeys-and-Essays-by-Christopher-Hitchens.pdf
    • http://ieuicufioao.myhome.cx/4557554557553556/The-Other-America-Poverty-in-the-United-States-by-Michael-Harrington.pdf