Malicious PDF — malware analysis report

Static analysis result for SHA-256 372b6c659d937161…

MALICIOUS

PDF

24.0 KB Created: 2020-03-20 02:10:55 +00:00 Authoring application: mPDF 5.7
MD5: 04f3f587e1f7a5f5c43c5e4f3155fe05 SHA-1: 2b59aa7836a472bda0d84844744238271a074979 SHA-256: 372b6c659d937161e32571ac5efc40108d1b3bb8ce947ad95224cf64e694dee8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links, a technique often used for SEO poisoning or to redirect users to malicious websites. The heuristic 'PDF_SEO_LINK_FARM' specifically identified this behavior, noting 29 generated links. The primary intent appears to be to lure users to click on these links, potentially leading to further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/1c00c00c07c07c09c06/James-A-Social-Justice-Commentary-on-the-Epistle-of-James-by-Jim-Reiher.pdf
    • http://laoieoa.myhome.cx/1c01c04c02c01c07c02/King-James-Version-Standard-Lesson-Commentary-1995-96-by-James-Fehl.pdf
    • http://laoieoa.myhome.cx/1c01c00c00c06c08c04/The-Illustrated-Bartsch-Vol-141-Commentary-James-Ensor-by-James-N-Elesh.pdf
    • http://laoieoa.myhome.cx/7c05c05c06c02c09/Commentary-on-St-Paul-s-First-Epistle-to-the-Corinthians-Vol-1-by-F-Godet.pdf
    • http://laoieoa.myhome.cx/9c05c02c06c02c00/The-First-Epistle-to-the-Corinthians-A-Commentary-on-the-Greek-Text-by-Anthony-C-Thiselton.pdf
    • http://laoieoa.myhome.cx/1c01c02c06c01c09c03/The-Epistle-of-Paul-to-the-Philippians-and-Colossians-An-Exegetical-and-Doctrinal-Commentary-by-Karl-Braune.pdf
    • http://laoieoa.myhome.cx/7c03c08c01c00c03/A-Commentary-on-the-Whole-Epistle-to-the-Hebrews-Vol-3-Being-the-Substance-of-Thirty-Years-Wednesday-s-Lectures-at-Blackfriars-London-by-William-Gouge.pdf
    • http://laoieoa.myhome.cx/4c04c04c02c04c06/JSA-Vol-1-Justice-Be-Done-by-James-Robinson.pdf
    • http://laoieoa.myhome.cx/5c02c07c01c08c06/Secret-Justice-by-James-W-Huston.pdf
    • http://laoieoa.myhome.cx/5c07c09c08c03/Blind-Justice-by-James-Scott-Bell.pdf
    • http://laoieoa.myhome.cx/5c06c06c02c05c09/Terrorism-and-Tyranny-Trampling-Freedom-Justice-and-Peace-to-Rid-the-World-of-Evil-by-James-Bovard.pdf
    • http://laoieoa.myhome.cx/5c01c02c00c05c02/The-Justice-of-Venice-Authorities-and-Liberties-in-the-Urban-Economy-1550-1700-by-James-E-Shaw.pdf
    • http://laoieoa.myhome.cx/9c09c02c04c05c04/Pilgrimage-from-the-Alps-to-the-Tiber-Or-The-Influence-of-Romanism-on-Trade-Justice-and-Knowledge-by-James-Aitken-1808-1890-Wylie.pdf
    • http://laoieoa.myhome.cx/2c00c01c05/Cross-Justice-Alex-Cross-23-by-James-Patterson.pdf
    • http://laoieoa.myhome.cx/4c04c07c04c01/Kill-Em-and-Leave-Searching-for-James-Brown-and-the-American-Soul-by-James-McBride.pdf
    • http://laoieoa.myhome.cx/5c01c09c00c01c05/James-B-Conant-Harvard-to-Hiroshima-and-the-Making-of-the-Nuclear-Age-by-James-G-Hershberg.pdf
    • http://laoieoa.myhome.cx/1c00c02c01c05c08/The-King-James-Only-Controversy-Can-You-Trust-the-Modern-Translations-by-James-R-White.pdf
    • http://laoieoa.myhome.cx/4c05c01c00c00c07/A-Journey-of-the-Imagination-The-Art-of-James-Christensen-by-Renwick-St-James.pdf
    • http://laoieoa.myhome.cx/3c08c05c07c00c00/Hunting-Season-The-Execution-of-James-Foley-Islamic-State-and-the-Real-Story-of-the-Kidnapping-Campaign-that-Started-a-War-by-James-Harkin.pdf
    • http://laoieoa.myhome.cx/4c07c08c00c00c06/Sex-and-Social-Justice-by-Martha-C-Nussbaum.pdf
    • http://laoieoa.myhome.cx/7c03c08c01c00c03/A-Commentary-on-the-Whole-Epistle-to-the-Hebrews-Vol-3-Being-the-Substance-o