Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c8357801ac873c6…

MALICIOUS

PDF

22.9 KB Created: 2020-03-20 13:14:17 +00:00 Authoring application: mPDF 5.7
MD5: 2271f8f1466d28ae61582635a62ac568 SHA-1: d593c39cea68c170527764b6b3c0ff208db59d03 SHA-256: 1c8357801ac873c69d6ae9c6798e329a652a3e45bfb895bbc218eb4c95d3fa9b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files, predominantly hosted on the domain 'ieuicufioao.myhome.cx'. This behavior is indicative of a link farm, often used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/9552550555552557/Baedeker-Greek-Islands-With-Map-by-Bernhard-Abend.pdf
    • http://ieuicufioao.myhome.cx/9552550554550555/Baedeker-France-by-Bernhard-Abend.pdf
    • http://ieuicufioao.myhome.cx/9552550555554559/Stricken-von-Mustern-f-r-Abend-Schals-und-Stolen-Abend-by-Unknown.pdf
    • http://ieuicufioao.myhome.cx/6557559559551559/Baedeker-s-London-And-Its-Environs-1900-by-Karl-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/4558558556553550/Great-Britain-Volume-1-Southern-England-amp-East-Anglia-Handbook-for-Travellers-by-Karl-Baedeker-by-Karl-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/4558558557558557/Tyrol-and-The-Dolomites-Including-the-Bavarian-Alps-Handbook-for-Travellers-by-Karl-Baedeker-by-Karl-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/9557550558556558/Baedeker-Israel-by-Jarrold-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/9557550558556559/Baedeker-s-London-by-Jarrold-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/9557550557559551/Baedeker-s-Mexico-by-Jarrold-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/9557550558557550/Baedeker-s-Switzerland-by-Jarrold-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/9557550557558555/Cologne-Baedeker-Guide-by-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/9557550557558556/Baedeker-s-France-by-Jarrold-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/4558558558550555/Switzerland-together-with-Chamonix-and-the-Italian-Lakes-Handbook-for-Travellers-by-Karl-Baedeker-by-Karl-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/4559550558552555/The-Greek-s-Pregnant-Lover-Traditional-Greek-Husbands-2-Greek-Tycoons-7-by-Lucy-Monroe.pdf
    • http://ieuicufioao.myhome.cx/4558558556553557/Spain-and-Portugal-Handbook-for-Travellers-by-Karl-Baedeker-by-Karl-Baedeker.pdf
    • http://ieuicufioao.myhome.cx/3553559550554559/Frommer-s-Vancouver-Island-the-Gulf-Islands-amp-the-San-Juan-Islands-by-Chris-McBeath.pdf
    • http://ieuicufioao.myhome.cx/1557553559557550/Atlas-of-Remote-Islands-Fifty-Islands-I-Have-Not-Visited-and-Never-Will-by-Judith-Schalansky.pdf
    • http://ieuicufioao.myhome.cx/1550555554559557551/Kontinent-Bernhard-Zur-Thomas-Bernhard-Rezeption-in-Europa-by-Wolfram-Bayer.pdf
    • http://ieuicufioao.myhome.cx/7553554557555559/Handbook-for-travellers-in-Greece-including-the-Ionian-Islands-continental-Greece-the-Peloponnese-the-islands-of-the-by-John-Murray.pdf
    • http://ieuicufioao.myhome.cx/1551553551550557552/Protection-Island-and-San-Jaun-Islands-National-Wildlife-Refuges-Comprehensive-Conservation-Plan-and-San-Juan-Islands-Wilderness-Stewardship-Plan-by-U-S-Fish-and-Wildlife-Service.pdf
    • http://ieuicufioao.myhome.cx/4558558557558557/Tyrol-and-The-Dolomites-Including-the-Bavarian-Alps-Handbook-f