Malicious PDF — malware analysis report

Static analysis result for SHA-256 18d590bc5d658e63…

MALICIOUS

PDF

20.9 KB Created: 2020-02-06 02:45:17 +00:00 Authoring application: mPDF 5.7
MD5: c3a0aaef50d039daeba25384dba6c978 SHA-1: 3450075349c42bdde63f05adbbeaddc9cd276b89 SHA-256: 18d590bc5d658e63e7ab7f32e46011b1c9857869dc567421a59cf914906aea70
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. The document body, though partially corrupted, contains these URLs, suggesting a link farm or SEO manipulation tactic. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://peldoaio.myhome.cx/73d53d63d43d33d2/The-Daughters-of-Edward-Darley-Boit-by-Frederic-P-Miller.pdf
    • http://peldoaio.myhome.cx/43d13d23d13d13d1/The-Doge-s-Daughter-by-Gabriella-West.pdf
    • http://peldoaio.myhome.cx/33d03d13d93d73d8/Dragonheart-by-Charles-Edward-Pogue.pdf
    • http://peldoaio.myhome.cx/13d13d43d73d83d23d6/The-Camel-s-Lament-by-Charles-Edward-Carryl.pdf
    • http://peldoaio.myhome.cx/83d43d93d43d83d8/Our-Liberty-Boys-of-17-Charleroi-Pennsylvania-by-Charles-Edward-1870--Presho.pdf
    • http://peldoaio.myhome.cx/93d53d43d73d1/Charles-and-Edward-A-Modern-Day-Pretty-Woman-by-Beau-Gar-on-De-La-Nuit.pdf
    • http://peldoaio.myhome.cx/23d73d13d83d23d8/Davy-and-the-Goblin-Or-What-Followed-Reading-Alice-s-Adventures-in-Wonderland-by-Charles-Edward-Carryl.pdf
    • http://peldoaio.myhome.cx/13d73d53d53d33d8/The-Daughters-Join-the-Party-The-Daughters-4-by-Joanna-Philbin.pdf
    • http://peldoaio.myhome.cx/13d13d13d23d53d43d7/Daughters-of-Darkness-Lara-Daughters-of-Darkness-3-by-Bianca-Iosivoni.pdf
    • http://peldoaio.myhome.cx/13d13d13d23d53d43d3/Daughters-of-Darkness-Scarlett-Daughters-of-Darkness-1-by-Bianca-Iosivoni.pdf
    • http://peldoaio.myhome.cx/23d33d33d73d1/The-Americanization-of-Edward-Bok-by-Edward-William-Bok.pdf
    • http://peldoaio.myhome.cx/83d63d63d63d83d4/The-21st-Golden-Age-of-Science-Fiction-MEGAPACK-TM-25-Stories-by-Edward-Wellen-by-Edward-Wellen.pdf
    • http://peldoaio.myhome.cx/63d73d93d63d43d9/Contes-de-Charles-Perrault-Fairy-Tales-of-Charles-Perrault-Bilingual-Book-in-French-and-English-dition-bilingue-fran-ais---anglais-Dual-Language-Illustrated-Book-for-Children-by-Charles-Perrault.pdf
    • http://peldoaio.myhome.cx/43d83d13d43d03d6/Ascending-Peculiarity-Edward-Gorey-on-Edward-Gorey-by-Edward-Gorey.pdf
    • http://peldoaio.myhome.cx/13d83d43d03d73d6/The-Rub-iy-t-of-Omar-Khayy-m-and-Other-Writings-by-Edward-Fitzgerald-by-Edward-FitzGerald.pdf
    • http://peldoaio.myhome.cx/93d03d83d13d03d8/Leopold-s-Way-Detective-Stories-of-Edward-D-Hoch-by-Edward-D-Hoch.pdf
    • http://peldoaio.myhome.cx/23d93d83d23d83d1/Edward-Gorey-His-Book-Cover-Art-and-Design-by-Edward-Gorey.pdf
    • http://peldoaio.myhome.cx/33d83d13d63d73d4/A-Halloween-Treat-amp-Edward-Gorey-s-Ghosts-by-Edward-Gorey.pdf
    • http://peldoaio.myhome.cx/33d13d13d23d53d6/Walk-on-the-Wild-Side-The-Best-Horror-Stories-of-Karl-Edward-Wagner-Volume-Two-by-Karl-Edward-Wagner.pdf
    • http://peldoaio.myhome.cx/33d13d53d03d7/A-Beautiful-Blue-Death-Charles-Lenox-Mysteries-1-by-Charles-Finch.pdf