Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ec1974943de2670…

MALICIOUS

PDF

21.4 KB Created: 2020-03-18 21:15:11 +00:00 Authoring application: mPDF 5.7
MD5: e7f9ce3c9007a175eec5e308a657621d SHA-1: 65effb45c9a383c122e0ce2ee620e93a905c22f5 SHA-256: 3ec1974943de2670209d9acc19b49e2f1f9528c7331b96607ed112632f3cfd6a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'laoieoa.myhome.cx'. This behavior is indicative of a link farm or a distribution point for malicious content, as flagged by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was unreadable, but the sheer volume of suspicious external links points to a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/5c09c03c04c08c06/Madame-Bovary-By-Gustave-Flaubert---Illustrated-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/5c03c08c06c04c00/Madame-Bovary-Biblioteca-de-Grandes-Escritores-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/6c03c09c01c01c06/Madame-Bovary-Translated-by-Eleanor-Marx-Aveling-with-an-Introduction-by-Ferdinand-Brunetiere-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/6c04c08c04c01c03/Textual-Hauntings-Studies-in-Flaubert-s-madame-Bovary-and-Mauriac-s-therese-Desqueyroux-by-Edward-J-Gallagher.pdf
    • http://laoieoa.myhome.cx/3c00c07c08c02/The-Letters-of-Gustave-Flaubert-1830-1857-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/5c08c00c03c00c03/Early-Writings-of-Gustave-Flaubert-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/5c08c00c02c03c09/Collected-Works-of-Gustave-Flaubert-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/9c00c07c03c07c09/Metamorphosen-Der-Siebten-Kunst-Franzosische-Romane-Des-19-Jahrhunderts-in-Ihrer-Filmischen-Umsetzung-Flaubert-Madame-Bovary-Claude-Chabrol-1991-Zola-Germinal-Claude-Berri-1993-by-Sabine-Seifert.pdf
    • http://laoieoa.myhome.cx/4c01c07c07c05/Three-Tales-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/2c02c04c08c02c03/Salambo-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/4c02c02c06c03/The-Temptation-of-St-Antony-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/5c08c00c03c03c04/Over-Strand-and-Field-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/2c08c03c03c03c06/Bouvard-and-Pecuchet-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/1c00c07c02c09c02c02/Das-Woerterbuch-Der-Ubernommen-Ideen-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/4c03c07c06c03c05/The-Desert-and-the-Dancing-Girls-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/7c00c03c09c04c04/Madame-Bovary-by-Rosemary-Lloyd.pdf
    • http://laoieoa.myhome.cx/2c09c08c01c05c01/Madame-Bovary-C-est-Moi-The-Great-Characters-of-Literature-and-Where-They-Came-From-by-Andr-Bernard.pdf
    • http://laoieoa.myhome.cx/7c06c08c04c09c01/Chere-Maitre-The-Correspondence-of-Gustave-Flaubert-and-George-Sand-by-Peter-Eyre.pdf
    • http://laoieoa.myhome.cx/5c03c09c07c06c05/L-Education-sentimentale-ditions-annot-e-Pr-c-d-e-de-La-Tentation-de-saint-Antoine-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/6c08c07c05c05c02/Novembre-November---zweisprachig-Franz-sisch-Deutsch-Edition-bilingue-fran-ais-allemand-by-Gustave-Flaubert.pdf
    • http://laoieoa.myhome.cx/5c08c00c03c00c03/Early-Writing