Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ef605f8fe253b9b…

MALICIOUS

PDF

28.7 KB Created: 2020-03-15 13:31:30 +00:00 Authoring application: mPDF 5.7
MD5: 75bd93e0be8c7474d3e00d683980433e SHA-1: b3b37e181067a40cb4093d1d457667dbe5a2f802 SHA-256: 3ef605f8fe253b9baf34fa3c30407cd571ed11db800e1d2e20955e3c1d73e0ab
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be directing users to a multitude of external websites, likely for SEO poisoning or to host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/33d43d23d53d73d6/Damnation-Island-Poor-Sick-Mad-amp-Criminal-in-19th-Century-New-York-by-Stacy-Horn.pdf
    • http://tanceubio.myhome.cx/23d53d23d63d83d7/The-Restless-Sleep-Inside-New-York-City-s-Cold-Case-Squad-by-Stacy-Horn.pdf
    • http://tanceubio.myhome.cx/13d83d93d33d33d0/The-Rich-Get-Richer-and-the-Poor-Get-Prison-Ideology-Class-and-Criminal-Justice-by-Jeffrey-H-Reiman.pdf
    • http://tanceubio.myhome.cx/63d63d33d53d8/Working-Women-of-Manila-in-the-19th-Century-by-Maria-Luisa-T-Camagay.pdf
    • http://tanceubio.myhome.cx/23d53d33d53d33d3/Food-and-Drink-in-Britain-From-the-Stone-Age-to-the-19th-Century-by-C-Anne-Wilson.pdf
    • http://tanceubio.myhome.cx/23d33d93d33d83d9/Sink-of-Atrocity-Crime-of-19th-Century-Dundee-by-Malcolm-Archibald.pdf
    • http://tanceubio.myhome.cx/83d23d83d13d03d5/The-Civilising-Offensive-New-Perspectives-on-Social-and-Educational-Reform-in-19th-Century-Belgium-by-Christoph-de-Spiegeleer.pdf
    • http://tanceubio.myhome.cx/13d03d13d13d53d23d7/Defining-the-Wind-The-Beaufort-Scale-and-How-a-19th-Century-Admiral-Turned-Science-Into-Poetry-by-Scott-Huler.pdf
    • http://tanceubio.myhome.cx/63d03d63d23d83d0/Les-MISERABLES-Vol-2-Cosette-EDITION-DE-LUXE-Illustrated-with-45-vintage-engravings-of-19th-century-artists-Detailed-Table-of-Contents-by-Victor-Hugo.pdf
    • http://tanceubio.myhome.cx/13d03d63d63d73d6/Horn-Horn-The-Horn-Horn-Series-by-A-D-T-McLellan.pdf
    • http://tanceubio.myhome.cx/93d53d63d53d73d0/Regency-Romance-The-Bet-of-the-Season-Historical-Arranged-Marriage-Romance-19th-Century-Victorian-Romance-by-Sarah-Thron.pdf
    • http://tanceubio.myhome.cx/73d83d53d13d13d3/The-Remarkable-Life-of-Kitty-McInerney-How-a-Poor-Irish-Immigrant-Raised-17-Children-in-Great-Depression-New-York-by-Christopher-Prince.pdf
    • http://tanceubio.myhome.cx/13d03d23d53d63d93d5/The-Contemporary-French-Writers-Selections-from-the-French-Writers-of-the-Second-Part-of-the-19th-Century-with-Literary-Notices-and-Historical-Geographical-Etymological-Grammatical-and-Explanatory-Notes-by-Rosine-Melle.pdf
    • http://tanceubio.myhome.cx/93d43d63d43d13d4/Poor-Poor-Ophelia-Krug-and-Kellog-1-by-Carolyn-Weston.pdf
    • http://tanceubio.myhome.cx/93d43d23d93d63d4/International-Criminal-Law-and-Sexual-Violence-Against-Women-The-Interpretation-of-Gender-in-the-Contemporary-International-Criminal-Trial-by-Daniela-Nadj.pdf
    • http://tanceubio.myhome.cx/23d33d83d13d0/Criminal-Vol-6-The-Last-of-the-Innocent-Criminal-6-by-Ed-Brubaker.pdf
    • http://tanceubio.myhome.cx/93d73d63d53d33d7/Island-Bauwerk-in-Island-Geographie-Island-Islander-Islandische-Geschichte-Islandische-Organisation-Kultur-Island-Medien-by-Quelle-Wikipedia.pdf
    • http://tanceubio.myhome.cx/53d03d03d23d33d5/New-York-Burning-Liberty-Slavery-and-Conspiracy-in-Eighteenth-Century-Manhattan-by-Jill-Lepore.pdf
    • http://tanceubio.myhome.cx/13d03d03d53d13d83d4/Horn-Horn-1-by-Peter-M-Ball.pdf
    • http://tanceubio.myhome.cx/43d43d73d43d93d7/Satan-s-Circus-Murder-Vice-Police-Corruption-and-New-York-s-Trial-of-the-Century-by-Mike-Dash.pdf
    • http://tanceubio.myhome.cx/23d33d93d33d83d9/Sink-of-Atro