Malicious PDF — malware analysis report

Static analysis result for SHA-256 196c639f1846ffb4…

MALICIOUS

PDF

16.6 KB Created: 2020-03-14 00:25:26 +00:00 Authoring application: mPDF 5.7
MD5: 51768cfce07c99b40b66ef3a2bf8ed4a SHA-1: f3f7604927c318834ff0dea01cb7d0a1c16c55a8 SHA-256: 196c639f1846ffb47cfc5507c0f2e9f23197341668205df9a6119b4ccb2f06ee
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the presence of numerous links suggests a potential redirection to malicious websites or phishing pages, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tikytsesapdf.myhome.cx/278c878c378c378c078c3/Deadly-Revelation-Deadly-Novel-Book-Two-by-Andrea-Johnson-Beck.pdf
    • http://tikytsesapdf.myhome.cx/578c378c578c678c378c4/Revenge-The-7th-Deadly-Sin-Alternate-Ending-G-Spot-2-The-Seven-Deadly-Sins-by-Noire.pdf
    • http://tikytsesapdf.myhome.cx/378c978c778c278c878c5/Deadly-Desire-Francesca-Cahill-Deadly-4-by-Brenda-Joyce.pdf
    • http://tikytsesapdf.myhome.cx/378c378c778c678c378c5/Deadly-Kisses-Deadly-Darkness-Trilogy-1-by-Kerri-Cuevas.pdf
    • http://tikytsesapdf.myhome.cx/178c378c378c478c378c3/Deadly-Love-Francesca-Cahill-Deadly-1-by-Brenda-Joyce.pdf
    • http://tikytsesapdf.myhome.cx/278c878c678c478c278c9/Deadly-Slumber-Deadly-Mystery-4-by-Victor-J-Banis.pdf
    • http://tikytsesapdf.myhome.cx/278c578c378c478c178c3/Deadly-Relations-Deadly-Trilogy-3-by-Alexa-Grace.pdf
    • http://tikytsesapdf.myhome.cx/278c578c378c478c178c2/Deadly-Holiday-Deadly-Trilogy-3-5-by-Alexa-Grace.pdf
    • http://tikytsesapdf.myhome.cx/278c878c078c778c878c0/Deadly-Crush-Deadly-Trilogy-1-by-Ashley-Stoyanoff.pdf
    • http://tikytsesapdf.myhome.cx/278c178c278c278c678c6/Deadly-Crush-Deadly-Trilogy-1-by-Ashley-Stoyanoff.pdf
    • http://tikytsesapdf.myhome.cx/278c578c878c078c978c8/Deadly-Obsession-Deadly-Vices-1-by-Kristine-Cayne.pdf
    • http://tikytsesapdf.myhome.cx/878c878c378c078c178c7/Deadly-Race-Deadly-2-by-Elke-Feuer.pdf
    • http://tikytsesapdf.myhome.cx/278c078c278c178c578c2/Deadly-Heat-Deadly-2-by-Cynthia-Eden.pdf
    • http://tikytsesapdf.myhome.cx/878c378c478c678c978c2/The-Third-Deadly-Sin-Deadly-Sins-4-by-Lawrence-Sanders.pdf
    • http://tikytsesapdf.myhome.cx/478c378c478c478c078c7/Deadly-Shadows-Deadly-1-by-Jaycee-Clark.pdf
    • http://tikytsesapdf.myhome.cx/278c478c678c378c178c1/Deadly-Bloodlines-Deadly-1-by-Elke-Feuer.pdf
    • http://tikytsesapdf.myhome.cx/878c778c478c478c3/Deadly-Lies-Deadly-3-by-Cynthia-Eden.pdf
    • http://tikytsesapdf.myhome.cx/178c178c778c578c4/Deadly-Fear-Deadly-1-by-Cynthia-Eden.pdf
    • http://tikytsesapdf.myhome.cx/278c578c078c378c578c1/Deadly-Games-Deadly-4-by-Jaycee-Clark.pdf
    • http://tikytsesapdf.myhome.cx/778c478c378c578c378c0/A-Circle-Deadly-Something-Wicked-Book-1-by-L-E-Falcone.pdf