Malicious PDF — malware analysis report

Static analysis result for SHA-256 31092f07578c987a…

MALICIOUS

PDF

23.3 KB Created: 2020-03-18 22:41:37 +00:00 Authoring application: mPDF 5.7
MD5: 9b1c57174430f53e06743c07da2d8d43 SHA-1: c78b7214b8d056959f5898fb2396d0d4389e9148 SHA-256: 31092f07578c987aaad35ec66196aefcb60c7a239bab7ccf76cd25c8fca308ff
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly indicated maliciousness. The primary attack pattern appears to be a link farm, likely intended to redirect users to malicious websites or for SEO poisoning. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/7622624622623621/Darkest-Italy-The-Nation-and-Stereotypes-of-the-Mezzogiorno-1860-1900-by-John-Dickie.pdf
    • http://weisncio.myhome.cx/7622623628627624/Mafia-Republic-Italy-s-Criminal-Curse-Cosa-Nostra-ndrangheta-and-Camorra-from-1946-to-the-Present-by-John-Dickie.pdf
    • http://weisncio.myhome.cx/5620626629623623/Naples-and-Napoleon-Southern-Italy-and-the-European-Revolutions-1780-1860-by-John-Anthony-Davis.pdf
    • http://weisncio.myhome.cx/4625624625621629/The-French-Impressionists-1860-1900-by-Camille-Mauclair.pdf
    • http://weisncio.myhome.cx/7622624621620627/Dickie-Dick-Dickens---Dickie-gegen-Chicago-by-Rolf-A-Becker.pdf
    • http://weisncio.myhome.cx/7622624621627620/Dirty-Dickie-s-Dynamite-Dick-Book-I-Dickie-at-18-by-V-J-Leone.pdf
    • http://weisncio.myhome.cx/2622625624621624/Road-to-Valor-A-True-Story-of-WWII-Italy-the-Nazis-and-the-Cyclist-Who-Inspired-a-Nation-by-Aili-McConnon.pdf
    • http://weisncio.myhome.cx/1625628626628627/Cosa-Nostra-A-History-of-the-Sicilian-Mafia-by-John-Dickie.pdf
    • http://weisncio.myhome.cx/8626623624623622/Lords-of-the-Underworld-Collection-1-The-Darkest-Night-The-Darkest-Kiss-The-Darkest-Pleasure-Lords-of-the-Underworld-1-3-by-Gena-Showalter.pdf
    • http://weisncio.myhome.cx/8626623624623628/Lords-of-the-Underworld-Collection-3-The-Darkest-Secret-The-Darkest-Surrender-The-Darkest-Seduction-Lords-of-the-Underworld-6-9-by-Gena-Showalter.pdf
    • http://weisncio.myhome.cx/6624625621622626/Art-in-Renaissance-Italy-by-John-T-Paoletti.pdf
    • http://weisncio.myhome.cx/5627624626623625/Eating-Italy-A-Culinary-Adventure-through-Italy-s-Best-Meals-by-Jeff-Michaud.pdf
    • http://weisncio.myhome.cx/5628625627627623/The-Conquest-of-Italy-and-South-Italy-by-the-Normans-by-Ferdinand-Chalandon.pdf
    • http://weisncio.myhome.cx/5628627626628620/Budapest-1900-A-Historical-Portrait-of-a-City-and-Its-Culture-by-John-Lukacs.pdf
    • http://weisncio.myhome.cx/8628620624626620/Hannibal-Crosses-the-Alps-The-Invasion-of-Italy-amp-the-Second-Punic-War-by-John-Prevas.pdf
    • http://weisncio.myhome.cx/3625627628629622/A-Death-in-Italy-The-Definitive-Account-of-the-Amanda-Knox-Case-by-John-Follain.pdf
    • http://weisncio.myhome.cx/2620621622626627/Church-And-State-In-Russia-The-Last-Years-Of-The-Empire-1900-1917-by-John-Shelton-Curtiss.pdf
    • http://weisncio.myhome.cx/3623628626626623/Turning-to-Nature-in-Germany-Hiking-Nudism-and-Conservation-1900-1940-by-John-Alexander-Williams.pdf
    • http://weisncio.myhome.cx/1626622629628620/Chaucerian-Polity-Absolutist-Lineages-and-Associational-Forms-in-England-and-Italy-by-David-John-Wallace.pdf
    • http://weisncio.myhome.cx/6628625629627624/John-Singer-Sargent-Figures-and-Landscapes-1900-1907-The-Complete-Paintings-Volume-VII-by-Richard-Ormond.pdf
    • http://weisncio.myhome.cx/