Malicious PDF — malware analysis report

Static analysis result for SHA-256 38f1e870069dc9fc…

MALICIOUS

PDF

29.4 KB Created: 2020-03-14 00:20:39 +00:00 Authoring application: mPDF 5.7
MD5: 0285ca48c53f2e85f57e408dcb5008f1 SHA-1: c2af03a202008bc7c51518b08feb1a09055a6b51 SHA-256: 38f1e870069dc9fc9e68d04140e41f617f82c285eaf7a2cd9c07297c27468f6a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs pointing to external PDF files on the domain 'rtuninnsi.myhome.cx'. This is indicative of a link farm or SEO poisoning attack, designed to lure users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9684

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/16a76a26a06a16a4/Zodiac-The-Shocking-True-Story-of-America-s-Most-Elusive-Serial-Killer-The-Shocking-True-Story-of-America-s-Most-Bizarre-Mass-Murderer-by-Robert-Graysmith.pdf
    • http://rtuninnsi.myhome.cx/16a06a46a16a46a1/Deranged-The-Shocking-True-Story-of-America-s-Most-Fiendish-Killer-by-Harold-Schechter.pdf
    • http://rtuninnsi.myhome.cx/26a26a26a16a26a2/Green-River-Running-Red-The-Real-Story-of-the-Green-River-Killer--America-s-Deadliest-Serial-Murderer-by-Ann-Rule.pdf
    • http://rtuninnsi.myhome.cx/26a76a46a46a16a5/Stalemate-A-Shocking-True-Story-of-Child-Abduction-and-Murder-by-John-Philpin.pdf
    • http://rtuninnsi.myhome.cx/66a66a96a96a3/The-Girl-Nobody-Wants---A-Shocking-True-Story-of-Child-Abuse-in-Ireland-by-Lily-O-39-Brien.pdf
    • http://rtuninnsi.myhome.cx/16a16a06a66a16a86a7/High-Achiever-The-Shocking-True-Story-of-One-Addict-s-Double-Life-by-Tiffany-Jenkins.pdf
    • http://rtuninnsi.myhome.cx/36a36a56a16a46a6/Beyond-Obsession-The-Shocking-True-Story-of-a-Teenage-Love-Affair-Turned-Deadly-by-Richard-Hammer.pdf
    • http://rtuninnsi.myhome.cx/46a46a36a76a56a2/Voyage-of-the-Damned-A-Shocking-True-Story-of-Hope-Betrayal-and-Nazi-Terror-by-Gordon-Thomas.pdf
    • http://rtuninnsi.myhome.cx/26a16a56a46a66a9/Deviant-The-Shocking-True-Story-of-Ed-Gein-the-Original-quot-Psycho-quot-by-Harold-Schechter.pdf
    • http://rtuninnsi.myhome.cx/16a06a86a56a26a86a0/Confessions-of-a-Guru-Wannabe-The-Shocking-True-Story-of-an-Attorney-Who-Lost-100-000-Online-as-an-Internet-Newbie-Before-Achieving-Breakthrough-and-How-the-Secrets-He-Learnt-Can-Help-You-Succeed-Too-by-Ope-Banwo.pdf
    • http://rtuninnsi.myhome.cx/56a96a16a86a26a5/Gosnell-The-Untold-Story-of-America-s-Most-Prolific-Serial-Killer-by-Ann-McElhinney.pdf
    • http://rtuninnsi.myhome.cx/16a16a96a56a26a66a7/Catch-Me-a-Killer-Serial-Murders-A-Profiler-s-True-Story-by-Micki-Pistorius.pdf
    • http://rtuninnsi.myhome.cx/26a86a06a06a76a0/Edward-Gein-America-s-Most-Bizarre-Murderer-by-Robert-H-Gollmar.pdf
    • http://rtuninnsi.myhome.cx/26a56a56a16a76a6/Killer-Cults-Shocking-True-Stories-of-the-Most-Dangerous-Cults-In-History-by-James-J-Boyle.pdf
    • http://rtuninnsi.myhome.cx/46a66a56a06a36a1/Death-in-the-Air-The-True-Story-of-a-Serial-Killer-the-Great-London-Smog-and-the-Strangling-of-a-City-by-Kate-Winkler-Dawson.pdf
    • http://rtuninnsi.myhome.cx/26a76a96a16a06a9/Inside-the-Mind-of-BTK-The-True-Story-Behind-the-Thirty-Year-Hunt-for-the-Notorious-Wichita-Serial-Killer-by-John-Edward-Douglas.pdf
    • http://rtuninnsi.myhome.cx/76a46a26a7/A-False-Report-A-True-Story-of-Rape-in-America-by-T-Christian-Miller.pdf
    • http://rtuninnsi.myhome.cx/66a56a56a76a86a6/Terrible-Typhoid-Mary-A-True-Story-of-the-Deadliest-Cook-in-America-by-Susan-Campbell-Bartoletti.pdf
    • http://rtuninnsi.myhome.cx/46a66a36a36a1/Adventures-of-a-Psychic-The-Fascinating-and-Inspiring-True-Life-Story-of-One-of-America-s-Most-Successful-Clairvoyants-by-Sylvia-Browne.pdf
    • http://rtuninnsi.myhome.cx/36a86a66a86a5/Marching-Powder-A-True-Story-of-Friendship-Cocaine-and-South-America-s-Strangest-Jail-by-Rusty-Young.pdf
    • http://rtuninnsi.myhome.cx/26a76a46a46a16a5/Stalemate-A-Shocking-True-Story-of-