Malicious PDF — malware analysis report

Static analysis result for SHA-256 29767a70cc7cb742…

MALICIOUS

PDF

17.0 KB Created: 2020-03-15 09:46:20 +00:00 Authoring application: mPDF 5.7
MD5: 2976fe8fe8dfb25f8ff810681de7902f SHA-1: d4b1e493ae99dfbdb3eed4f2cf84fcfa6b76e627 SHA-256: 29767a70cc7cb742e4a72231818ca67c2716b1bbdc7d24521a0833bbe6ab161f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'weasciaoak.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weasciaoak.myhome.cx/82d42d62d82d62d6/Les-Six-Voyages-de-Jean-Baptiste-Tavernier-Ecuyer-Baron-D-Aubonne-Qu-il-a-Fait-en-Turquie-en-Perse-et-aux-Indes-pendant-quarante-ans-Volume-3-by-Jean-Baptiste-Tavernier.pdf
    • http://weasciaoak.myhome.cx/62d32d02d92d12d6/L-Abyssin-Relation-des-extraordinaires-voyages-de-Jean-Baptiste-Poncet-ambassadeur-du-N-gus-aupr-s-de-Sa-Majest-Louis-XIV-by-Jean-Christophe-Rufin.pdf
    • http://weasciaoak.myhome.cx/82d62d72d32d62d2/M-moires-du-g-n-ral-baron-de-Marbot-Tome-2-by-Jean-Baptiste-de-Marbot.pdf
    • http://weasciaoak.myhome.cx/82d42d62d62d72d0/Bertrand-Tavernier-cin-aste-insurg-by-Jean-Luc-Douin.pdf
    • http://weasciaoak.myhome.cx/82d42d52d92d12d5/Voyages-en-Perse-by-Jean-Chardin.pdf
    • http://weasciaoak.myhome.cx/52d42d42d22d82d4/Verlaine-by-Jean-Baptiste-Baronian.pdf
    • http://weasciaoak.myhome.cx/72d22d32d32d52d9/La-m-taphysique-du-mou-by-Jean-Baptiste-Botul.pdf
    • http://weasciaoak.myhome.cx/52d12d72d52d42d7/Une-ducation-libertine-by-Jean-Baptiste-Del-Amo.pdf
    • http://weasciaoak.myhome.cx/62d82d02d52d42d0/Baudelaire-by-Jean-Baptiste-Baronian.pdf
    • http://weasciaoak.myhome.cx/82d12d62d42d72d3/Jours-de-Mai-by-Jean-Baptiste-Harang.pdf
    • http://weasciaoak.myhome.cx/62d02d92d02d52d4/Rimbaud-by-Jean-Baptiste-Baronian.pdf
    • http://weasciaoak.myhome.cx/62d52d42d42d32d6/Douze-le-by-Jean-Baptiste-Piolet.pdf
    • http://weasciaoak.myhome.cx/52d12d42d02d22d3/R-gne-animal-by-Jean-Baptiste-Del-Amo.pdf
    • http://weasciaoak.myhome.cx/82d42d02d42d72d0/Le-Grand-Chalababa-by-Jean-Baptiste-Baronian.pdf
    • http://weasciaoak.myhome.cx/82d42d02d42d52d5/Lord-John-by-Jean-Baptiste-Baronian.pdf
    • http://weasciaoak.myhome.cx/62d02d12d62d72d2/La-fausse-marquise-m-by-Jean-Baptiste-Dubois.pdf
    • http://weasciaoak.myhome.cx/82d32d82d82d42d0/Sonate-de-l-assassin-by-Jean-Baptiste-Destremau.pdf
    • http://weasciaoak.myhome.cx/82d42d02d42d52d8/Meurtre-Waterloo-by-Jean-Baptiste-Baronian.pdf
    • http://weasciaoak.myhome.cx/52d42d52d02d12d1/G-opolitique-du-sport-by-Jean-Baptiste-Gu-gan.pdf
    • http://weasciaoak.myhome.cx/62d32d22d62d52d0/-Por-qu-vuelan-los-aviones-by-Jean-Baptiste-Touchard.pdf
    • http://weasciaoak