Malicious PDF — malware analysis report

Static analysis result for SHA-256 2be274388423e423…

MALICIOUS

PDF

15.1 KB Created: 2020-03-18 16:41:21 +00:00 Authoring application: mPDF 5.7 First seen: 2021-06-20
MD5: e4c819ee609a34090b43332c4bb7a5ad SHA-1: fa0976fd37c6270b05e30452ca3c1df76253356f SHA-256: 2be274388423e423547c6732dab69e1bbf14210daff6d8de8ee17a84b3bfb697
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to a domain that appears to be hosting a collection of PDF files, likely as part of a link farm or SEO poisoning scheme. The ML_NYX_PDF_MALICIOUS classifier also flagged this document as malicious. The embedded URLs are the primary IOCs, suggesting the document's purpose is to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1557550552559554/Falling-into-Exposure-Falling-2-by-A-Zavarelli.pdf In PDF document text
    • http://ieuicufioao.myhome.cx/1557550552557551/Falling-into-Temptation-Falling-1-by-A-Zavarelli.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/9556554556550/Falling-in-Fiji-Falling-in-Paradise-1-by-Casey-Hagen.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1550551554559557/The-Falling-of-Love-Falling-1-by-Marisa-Oldham.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/9558556559554551/Edge-of-Falling-Falling-2-by-Valia-Lind.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/3559557557558551/The-Falling-of-Hope-Falling-3-by-Marisa-Oldham.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/3554552552554554/Falling-into-Forever-Falling-into-You-2-by-Lauren-Abrams.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2550552552553551/Falling-for-Him-4-Falling-for-Him-4-by-Jessica-Gray.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/4554558552554/This-is-Falling-Falling-1-by-Ginger-Scott.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1552553558551556/Falling-Away-Falling-2-by-Devon-Ashley.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/3554551550555/Falling-into-You-Falling-1-by-Jasinda-Wilder.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2550552552553554/Falling-for-Him-5-Falling-for-Him-5-by-Jessica-Gray.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/5552554553558554/Falling-for-the-Billionaire-The-Complete-Series-Falling-for-the-Billionaire-1-3-by-Victoria-Villeneuve.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1550555551554551554/Falling-Fast-Falling-Fast-1-by-Tina-Wainscott.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/8551552558558/Falling-Stars-Falling-Stars-1-by-Sadie-Grubor.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2554556557551550/Falling-Stars-Falling-Stars-1-by-Xio-Axelrod.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/3559558551555559/Falling-for-Her-Fake-Boyfriend-Falling-for-Her-Fake-Boyfriend-1-by-Ann-King.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1551553555554551553/Falling-by-J-D-Obermeier.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2552553559553558/Falling-for-Him-by-C-L-Mustafic.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1552554552558553/The-Sky-Is-Falling-by-H-J-Rethuan.pdfIn PDF document text