Malicious PDF — malware analysis report

Static analysis result for SHA-256 41ca8d59c7056b9c…

MALICIOUS

PDF

17.0 KB Created: 2020-03-18 18:08:23 +00:00 Authoring application: mPDF 5.7
MD5: beb362fbbfbf8ea89b0987cda9aae1db SHA-1: 2456b42861b5e54a44cb8151881fbc7471a31abe SHA-256: 41ca8d59c7056b9c6df5e161a1bce5ae5fae8a265d0d82100543ba06ea353ac9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The document body confirms the presence of these URLs, suggesting a link farm or redirection scheme designed to lead users to potentially malicious content hosted on the `weisncio.myhome.cx` domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1620628624627627623/Shit-Happens-Desi-Boy-in-America-by-Karan-Puri.pdf
    • http://weisncio.myhome.cx/1620628624629620620/Shit-Happens-by-Karan-Puri.pdf
    • http://weisncio.myhome.cx/1620628625620623625/Shit-Test-Mastery-Pass-women-s-shit-tests-with-flying-colors-by-Strategic-Lothario.pdf
    • http://weisncio.myhome.cx/1629627624621624/Keep-off-The-Grass-by-Karan-Bajaj.pdf
    • http://weisncio.myhome.cx/3623629621624623/The-Yoga-of-Max-s-Discontent-by-Karan-Bajaj.pdf
    • http://weisncio.myhome.cx/4627625625622622/A-Book-by-Desi-Arnaz.pdf
    • http://weisncio.myhome.cx/1627629620622623/Accidental-Intent-by-Desi-Moon.pdf
    • http://weisncio.myhome.cx/9627621626625/The-Dreaming-Reality-by-Noor-Anand-and-Karan-Kapoor.pdf
    • http://weisncio.myhome.cx/5626627626624625/Desi-Pere-Swirling-Secrets-1-by-Roze-Wallin.pdf
    • http://weisncio.myhome.cx/1625622628621620/The-Case-of-the-Man-Who-Died-Laughing-Vish-Puri-2-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/3625624626621626/The-Case-of-the-Love-Commandos-Vish-Puri-4-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/3622625625623625/The-Case-of-the-Missing-Servant-Vish-Puri-1-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/9621627622627627/Liberalismul-pro-i-contra---O-idee-ce-refuz-s-moar-de-i-nu-tie-ce-o-ine-n-via-by-Sorin-Adam-Matei.pdf
    • http://weisncio.myhome.cx/3625628624627627/The-Case-of-the-Man-Who-Died-Laughing-Vish-Puri-Most-Private-Investigator-Series-Book-2-by-Tarquin-Hall.pdf
    • http://weisncio.myhome.cx/1621625626628625623/Fighting-and-Negotiating-with-Armed-Groups-The-difficulty-of-securing-strategic-outcomes-Adelphi-Book-459-by-Samir-Puri.pdf
    • http://weisncio.myhome.cx/1626620629625621/Jaya-s-Compromise-An-Indian-erotic-sex-story-desi-erotic-tales-Book-1-by-Reema.pdf
    • http://weisncio.myhome.cx/1620628624627626627/FROM-SUGAR-TO-SHIT-by-Mr-777.pdf
    • http://weisncio.myhome.cx/1620628624627626621/It-Is-Just-You-Everything-s-Not-Shit-by-Steve-Stack.pdf
    • http://weisncio.myhome.cx/1620628624627622627/Shit-My-Dad-Never-Says-by-Oscar-Wilde.pdf
    • http://weisncio.myhome.cx/1620628624627626628/From-Sugar-To-Shit-by-V-Brown.pdf
    • http://weisncio.myhome.cx/96216276