Malicious PDF — malware analysis report

Static analysis result for SHA-256 329179718bf05272…

MALICIOUS

PDF

22.2 KB Created: 2020-03-18 16:33:59 +00:00 Authoring application: mPDF 5.7
MD5: 11b5f54fd49b66bc5a6f6f6396f8e7dd SHA-1: b92254b47e45aca5b78d95bd9be66059aef9ff8e SHA-256: 329179718bf05272150b8192c51667d2274ccf35bd61817499f8d68081df7c1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which are likely used to direct users to malicious websites. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1555553555557/Facts-of-Life-by-Maureen-Howard.pdf
    • http://ieuicufioao.myhome.cx/2556556557556552/1700-Scenes-from-London-Life-by-Maureen-Waller.pdf
    • http://ieuicufioao.myhome.cx/3552553555551550/London-1945-Life-in-the-Debris-of-War-by-Maureen-Waller.pdf
    • http://ieuicufioao.myhome.cx/5550551556550/Love-Love-Love-And-Other-Essays-Light-Reflections-on-Love-Life-and-Death-by-Charles-Taliaferro.pdf
    • http://ieuicufioao.myhome.cx/1550555558553558556/Introvert-Doodles-An-Illustrated-Collection-of-Life-s-Awkward-Moments-by-Maureen-Marzi-Wilson.pdf
    • http://ieuicufioao.myhome.cx/1551554550559553555/Fu-ball-Land-DDR-by-Frank-Willmann.pdf
    • http://ieuicufioao.myhome.cx/9554559556558552/Schuldig-Krimireihe-Hartmann-by-Jens-R-Willmann.pdf
    • http://ieuicufioao.myhome.cx/1550555558554553553/Introvert-Doodles-An-Illustrated-Look-at-Introvert-Life-in-an-Extrovert-World-by-Maureen-Marzi-Wilson.pdf
    • http://ieuicufioao.myhome.cx/1551554550558559554/Todesmarsch-durch-Russland-Mein-Weg-in-die-Kriegsgefangenschaft-by-Klaus-Willmann.pdf
    • http://ieuicufioao.myhome.cx/1551554550557551551/U-188-A-German-Submariner-s-Account-of-the-War-at-Sea-1941-1945-by-Klaus-Willmann.pdf
    • http://ieuicufioao.myhome.cx/1551554550557556553/The-Annotated-Guide-for-Rns-to-the-Texas-Nursing-Practice-ACT-10th-Edition-by-James-H-Willmann.pdf
    • http://ieuicufioao.myhome.cx/1550554551557553555/Breathless-love-after-life-Miss-you-Breathless-love-after-life-Book-1-by-Ritu.pdf
    • http://ieuicufioao.myhome.cx/3552551554555556/The-New-Love-Triangle-Your-Practical-Guide-to-a-Love-Filled-Life-by-Allen-Vaysberg.pdf
    • http://ieuicufioao.myhome.cx/4557558559553558/Unconditional-Love-Love-Life-amp-Happiness-3-by-Sheena-Binkley.pdf
    • http://ieuicufioao.myhome.cx/2556551557552553/Love-Your-Life-Not-Theirs-7-Money-Habits-for-Living-the-Life-You-Want-by-Rachel-Cruze.pdf
    • http://ieuicufioao.myhome.cx/6555553559550554/Queer-Eye-Love-Yourself-Love-Your-Life-by-Antoni-Porowski.pdf
    • http://ieuicufioao.myhome.cx/7557551551557559/My-Life-with-Audree-A-Deaf-Couple-s-Sixty-Eight-Years-of-Life-Love-and-Pursuing-Dreams-by-Kenneth-W-Norton.pdf
    • http://ieuicufioao.myhome.cx/5557554551552/Mid-Life-Love-Mid-Life-Love-1-by-Whitney-G-.pdf
    • http://ieuicufioao.myhome.cx/1559552556553559/Life-on-Pause-Love-Life-1-by-Erin-McLellan.pdf
    • http://ieuicufioao.myhome.cx/2558551551555557/Love-s-Look-Ozark-Life-by-Rolland-Love.pdf
    • http://ieuicufioao.myhome.cx/1550555558554553553/Introvert-Doodles-An-Illustrated-Look-at-In