Malicious PDF — malware analysis report

Static analysis result for SHA-256 27c6c3ca2d6dc0b3…

MALICIOUS

PDF

22.1 KB Created: 2020-03-18 21:53:55 +00:00 Authoring application: mPDF 5.7
MD5: c10913ae7c820fbd58f37f1feb0348a3 SHA-1: 139a03e62208975ad0035c7fc99a9de0b8022e41 SHA-256: 27c6c3ca2d6dc0b3a338fd2fc00fd5d7f30c3c62f30429fab6eddd89bf1ce369
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates that the PDF is part of a link farm, likely to distribute malicious content or for SEO manipulation. The embedded URLs point to various PDF files hosted on the same domain, suggesting a coordinated effort to host or link to malicious documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://peldoaio.myhome.cx/43d43d33d73d83d6/Buffy-the-Vampire-Slayer-Remaining-Sunlight-Buffy-the-Vampire-Slayer-Comic-11-Buffy-Season-3-by-Andi-Watson.pdf
    • http://peldoaio.myhome.cx/43d33d73d93d23d2/Buffy-the-Vampire-Slayer-Oz-Buffy-the-Vampire-Slayer-Comic-20-Buffy-Season-4-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/23d63d93d93d23d0/Buffy-Cazavampiros-Inmortal-Buffy-the-Vampire-Slayer-Season-3-9-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/13d03d23d13d03d33d8/Buffy-The-Vampire-Slayer-Staffel-8-Bd-2-Wie-t-tet-man-eine-J-gerin-Buffy-the-Vampire-Slayer---Staffel-8-by-Joss-Whedon.pdf
    • http://peldoaio.myhome.cx/33d03d63d13d03d5/Buffy-the-Vampire-Slayer-Billy-the-Vampire-Slayer-Part-1-Season-9-14-by-Jane-Espenson.pdf
    • http://peldoaio.myhome.cx/13d03d23d13d23d13d7/Buffy-the-Vampire-Slayer-Staffel-10-Band-2-W-nsche-Buffy-the-Vampire-Slayer---Staffel-10-by-Christos-Gage.pdf
    • http://peldoaio.myhome.cx/13d03d23d13d03d43d6/Buffy-the-Vampire-Slayer-Staffel-8-Bd-5-Harmony-live-Buffy-the-Vampire-Slayer---Staffel-8-by-Joss-Whedon.pdf
    • http://peldoaio.myhome.cx/23d73d03d53d23d0/Buffy-Cazavampiros-El-Libro-de-los-Cuatros-Buffy-the-Vampire-Slayer-Novelas-by-Nancy-Holder.pdf
    • http://peldoaio.myhome.cx/53d63d63d83d73d3/Why-Buffy-Matters-The-Art-of-Buffy-the-Vampire-Slayer-by-Rhonda-V-Wilcox.pdf
    • http://peldoaio.myhome.cx/73d83d03d83d6/Revenant-Buffy-the-Vampire-Slayer-Season-3-11-by-Mel-Odom.pdf
    • http://peldoaio.myhome.cx/33d03d43d63d13d6/Buffy-the-Vampire-Slayer-On-Your-Own-Part-1-Season-9-6-by-Andrew-Chambliss.pdf
    • http://peldoaio.myhome.cx/33d03d63d13d33d1/Buffy-the-Vampire-Slayer-Guarded-Part-3-Season-9-13-by-Andrew-Chambliss.pdf
    • http://peldoaio.myhome.cx/23d83d83d33d23d3/Buffy-the-Vampire-Slayer-Freefall-Part-3-Season-9-3-by-Andrew-Chambliss.pdf
    • http://peldoaio.myhome.cx/93d13d33d53d73d6/Buffy-the-Vampire-Slayer-Die-R-ckkehr-der-J-gerin-Season-8-1-by-Georges-Jeanty.pdf
    • http://peldoaio.myhome.cx/43d43d13d23d6/The-Book-of-Fours-Buffy-the-Vampire-Slayer-Season-3-23-by-Nancy-Holder.pdf
    • http://peldoaio.myhome.cx/73d63d33d63d63d3/Les-fautes-du-p-re-Buffy-the-Vampire-Slayer-Season-3-1-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/33d93d63d93d13d7/Prime-Evil-Buffy-the-Vampire-Slayer-Season-3-10-by-Diana-G-Gallagher.pdf
    • http://peldoaio.myhome.cx/33d43d23d23d63d1/Buffy-the-Vampire-Slayer-The-Script-Book-Season-Two-Vol-1-by-Gertrude-Pocket.pdf
    • http://peldoaio.myhome.cx/73d83d93d03d03d9/Croqueuses-de-cadavres-Buffy-the-Vampire-Slayer-Season-3-4-by-John-Passarella.pdf
    • http://peldoaio.myhome.cx/33d03d43d83d23d9/Buffy-the-Vampire-Slayer-Guarded-Season-9-Volume-3-by-Andrew-Chambliss.pdf