Malicious PDF — malware analysis report

Static analysis result for SHA-256 35181ac4a2068aac…

MALICIOUS

PDF

15.9 KB Created: 2020-03-18 22:07:35 +00:00 Authoring application: mPDF 5.7
MD5: dcf04d744ab778cc5a910a8f8bb12123 SHA-1: 1e01533b37e2bd93ff6cb87878ac288889c7d416 SHA-256: 35181ac4a2068aace7f3df7a27ed70934005547ad66a7a0149fc8022db2e8ddb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm with 21 external links, all pointing to PDFs on the domain 'weisncio.myhome.cx'. This is a common technique for SEO poisoning or distributing malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/5628629628621629/Hunter-x-Hunter-Vol-33-Hunter-x-Hunter-33-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629627626620/Hunter-x-Hunter-Vol-17-Hunter-x-Hunter-17-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628621621/Hunter-x-Hunter-Vol-26-Hunter-x-Hunter-26-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628627620/Hunter-x-Hunter-Vol-23-Hunter-x-Hunter-23-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628621624/Hunter-x-Hunter-Vol-28-Hunter-x-Hunter-28-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628626625/Hunter-x-Hunter-Vol-20-Hunter-x-Hunter-20-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629628620625/Hunter-x-Hunter-Vol-19-Hunter-x-Hunter-19-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/5628629627626621/Hunter-x-Hunter-Vol-11-Hunter-x-Hunter-11-by-Yoshihiro-Togashi.pdf
    • http://weisncio.myhome.cx/4620622629622628/Bad-Moon-Rising-Dark-Hunter-14-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://weisncio.myhome.cx/4623620625621622/Bad-Moon-Rising-Dark-Hunter-14-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://weisncio.myhome.cx/2628625623621625/The-Renegade-Hunter-Argeneau-12-Rogue-Hunter-3-by-Lynsay-Sands.pdf
    • http://weisncio.myhome.cx/1629622620621623/The-Guardian-Dream-Hunter-5-Were-Hunter-9-Hellchaser-4-by-Sherrilyn-Kenyon.pdf
    • http://weisncio.myhome.cx/4621625629627/The-Immortal-Hunter-Argeneau-11-Rogue-Hunter-2-by-Lynsay-Sands.pdf
    • http://weisncio.myhome.cx/4627627628622620/Unleash-the-Night-Dark-Hunter-9-Were-Hunter-4-by-Sherrilyn-Kenyon.pdf
    • http://weisncio.myhome.cx/4623629622626627/The-Immortal-Hunter-Argeneau-11-Rogue-Hunter-2-by-Lynsay-Sands.pdf
    • http://weisncio.myhome.cx/2624628622623621/The-Hunter-Robert-Hunter-Series-0-5-by-Chris-Carter.pdf
    • http://weisncio.myhome.cx/4623620625625627/No-Mercy-Dark-Hunter-19-Were-Hunter-6-by-Sherrilyn-Kenyon.pdf
    • http://weisncio.myhome.cx/1626624625624625/Rogue-Hunter-Quest-of-the-Hunter-by-Kevis-Hendrickson.pdf
    • http://weisncio.myhome.cx/3622620627627622/The-Teachings-of-Howard-W-Hunter-Fourteenth-President-of-the-Church-of-Jesus-Christ-of-Latter-Day-Saints-by-Howard-W-Hunter.pdf
    • http://weisncio.myhome.cx/4623627625623629/Hunter-s-Tracks-by-John-A-Hunter.pdf