Malicious PDF — malware analysis report

Static analysis result for SHA-256 37d66d16c8e3a408…

MALICIOUS

PDF

15.1 KB Created: 2020-03-18 18:08:24 +00:00 Authoring application: mPDF 5.7
MD5: d83702f09eaa75585659db589a94f8a9 SHA-1: f4ffead1f12a72a29dad62dafa0a800ace3e38c1 SHA-256: 37d66d16c8e3a408c82a7e91f56e0656237aa0c816150fdf7df9f65e468c8908
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links, all pointing to the same domain, 'weisncio.myhome.cx'. This behavior is indicative of a link farm, likely intended to drive traffic or distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9200

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1620628624629620620/Shit-Happens-by-Karan-Puri.pdf
    • http://weisncio.myhome.cx/1620628624627627623/Shit-Happens-Desi-Boy-in-America-by-Karan-Puri.pdf
    • http://weisncio.myhome.cx/1620628625620623625/Shit-Test-Mastery-Pass-women-s-shit-tests-with-flying-colors-by-Strategic-Lothario.pdf
    • http://weisncio.myhome.cx/1629627624621624/Keep-off-The-Grass-by-Karan-Bajaj.pdf
    • http://weisncio.myhome.cx/3623629621624623/The-Yoga-of-Max-s-Discontent-by-Karan-Bajaj.pdf
    • http://weisncio.myhome.cx/9627621626625/The-Dreaming-Reality-by-Noor-Anand-and-Karan-Kapoor.pdf
    • http://weisncio.myhome.cx/1625622628621620/The-Case-of-the-Man-Who-Died-Laughing-Vish-Puri-2-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/3622625625623625/The-Case-of-the-Missing-Servant-Vish-Puri-1-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/3625624626621626/The-Case-of-the-Love-Commandos-Vish-Puri-4-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/3625628624627627/The-Case-of-the-Man-Who-Died-Laughing-Vish-Puri-Most-Private-Investigator-Series-Book-2-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/1621625626628625623/Fighting-and-Negotiating-with-Armed-Groups-The-difficulty-of-securing-strategic-outcomes-Adelphi-Book-459-by-Samir-Puri.pdf
    • http://weisncio.myhome.cx/1620628624627626627/FROM-SUGAR-TO-SHIT-by-Mr-777.pdf
    • http://weisncio.myhome.cx/1620628625620623624/King-Shit-and-the-Fat-Ass-by-Joe-Brewster.pdf
    • http://weisncio.myhome.cx/3625621622622629/More-Shit-My-Dad-Says-by-Justin-Halpern.pdf
    • http://weisncio.myhome.cx/1620628624627626621/It-Is-Just-You-Everything-s-Not-Shit-by-Steve-Stack.pdf
    • http://weisncio.myhome.cx/1620628624628622624/Cat-shit-one-0-by-Motofumi-Kobayashi.pdf
    • http://weisncio.myhome.cx/1620628624628622627/No-Shit-There-I-Was-by-Michael-Hodgson.pdf
    • http://weisncio.myhome.cx/1620628624628621629/You-Have-Too-Much-Shit-by-Chris-Thomas.pdf
    • http://weisncio.myhome.cx/1620628624627622627/Shit-My-Dad-Never-Says-by-Oscar-Wilde.pdf
    • http://weisncio.myhome.cx/1620628624627626628/From-Sugar-To-Shit-by-V-Brown.pdf
    • http://weisncio.myhome.cx/1621625626628625623/Fighting-and-Negotiating-with-