Malicious PDF — malware analysis report

Static analysis result for SHA-256 17c0b70172f9a2fa…

MALICIOUS

PDF

19.0 KB Created: 2020-03-20 11:21:27 +00:00 Authoring application: mPDF 5.7
MD5: c4dc1e6d8d2534a9eff5c6da0118b56b SHA-1: 71bcbbaf2a6f7a4670851bc54f3d97a69f7c5918 SHA-256: 17c0b70172f9a2faca925dd97a6f18696534a33c999c48460686fa8da43271e5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, hosted on the suspicious domain 'ieuicufioao.myhome.cx'. This behavior is indicative of a link farm or a method to distribute malicious content disguised as legitimate documents. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1551551551554552556/The-Cockroach-Hat-by-Terry-Bisson.pdf
    • http://ieuicufioao.myhome.cx/4555550556559551/Doctor-Who-Day-of-the-Cockroach-by-Steve-Lyons.pdf
    • http://ieuicufioao.myhome.cx/2552554554558/The-Cockroach-Invasion-by-Sherry-L-Meinberg.pdf
    • http://ieuicufioao.myhome.cx/5555558556556/Galahad-Schwartz-And-The-Cockroach-Army-by-Morgan-Nyberg.pdf
    • http://ieuicufioao.myhome.cx/2557555555554/Martina-the-Beautiful-Cockroach-A-Cuban-Folktale-by-Carmen-Agra-Deedy.pdf
    • http://ieuicufioao.myhome.cx/1551555558553550559/Dance-Is-the-Language-of-the-Gods-The-Chitrasena-School-and-the-Traditional-Roots-of-Sri-Lankan-Stage-Dance-by-Marianne-N-rnberger.pdf
    • http://ieuicufioao.myhome.cx/4555554550556552/Dance-Dance-Revolution-by-Cathy-Park-Hong.pdf
    • http://ieuicufioao.myhome.cx/1554555553551556/Dance-in-the-Dark-Dance-with-the-Devil-2-by-Megan-Derr.pdf
    • http://ieuicufioao.myhome.cx/3551550554553553/A-Dangerous-Dance-Save-the-Last-Dance-1-by-Jude-Johnson.pdf
    • http://ieuicufioao.myhome.cx/2555553551558556/Dance-of-the-Seven-Veils-Dance-1-by-Cris-Anson.pdf
    • http://ieuicufioao.myhome.cx/3550553550553554/Dance-of-the-Seven-Veils-Dance-1-by-Cris-Anson.pdf
    • http://ieuicufioao.myhome.cx/1557554554558551/Dance-for-Me-1-Dance-for-Me-1-by-Holly-Stone.pdf
    • http://ieuicufioao.myhome.cx/1554555553559556/Pole-Dance-Dance-1-by-J-A-Hornbuckle.pdf
    • http://ieuicufioao.myhome.cx/8552551553556554/Irish-Dance-Riverdance-the-Pirate-Queen-Irish-Stepdance-Ceilidh-Clare-Lancers-Set-Feis-Celtic-Tiger-Live-Garryowen-Sean-Nos-Dance-by-Source-Wikipedia.pdf
    • http://ieuicufioao.myhome.cx/8555557555/Dance-of-Thieves-Dance-of-Thieves-1-by-Mary-E-Pearson.pdf
    • http://ieuicufioao.myhome.cx/1558559552558553/Dance-with-the-Devil-Dance-with-the-Devil-1-by-Megan-Derr.pdf
    • http://ieuicufioao.myhome.cx/3559555557551551/Dance-In-The-Vampire-Bund-Vol-1-Dance-in-the-Vampire-Bund-1-by-Nozomu-Tamaki.pdf
    • http://ieuicufioao.myhome.cx/9558551551557558/Dance-in-the-Vampire-Bund-5-Dance-in-the-Vampire-Bund-9-10-by-Nozomu-Tamaki.pdf
    • http://ieuicufioao.myhome.cx/2551555557559551/Dance-in-the-Vampire-Bund-Vol-2-Dance-in-the-Vampire-Bund-2-by-Nozomu-Tamaki.pdf
    • http://ieuicufioao.myhome.cx/2553551552551558/Dance-in-the-Vampire-Bund-Vol-3-Dance-in-the-Vampire-Bund-3-by-Nozomu-Tamaki.pdf