Malicious PDF — malware analysis report

Static analysis result for SHA-256 46f4ebe3fb3dc405…

MALICIOUS

PDF

16.2 KB Created: 2020-03-12 02:12:45 +00:00 Authoring application: mPDF 5.7
MD5: a06158986fa7530a6ec72aa67da28a1c SHA-1: e7cc208cd77225f6480fd50f46c0e77f316816d1 SHA-256: 46f4ebe3fb3dc4056d841bf19a433f5c9c9cd9641a9d1a43d4d01251700a5b9e
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to a single domain, identified as a link farm. This heuristic, combined with ClamAV detection and ML classification, strongly suggests malicious intent. The document body, though heavily obfuscated, contains these URLs, indicating a likely attempt to redirect the user to potentially harmful content hosted on 'ieuicufioao.myhome.cx'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Malware.Agent-9909946-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Malware.Agent-9909946-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/3552559558553/Gabriel-s-Rapture-Gabriel-s-Inferno-2-by-Sylvain-Reynard.pdf
    • http://ieuicufioao.myhome.cx/1550551557556/Gabriel-s-Redemption-Gabriel-s-Inferno-3-by-Sylvain-Reynard.pdf
    • http://ieuicufioao.myhome.cx/3553554550553559/Gabriel-s-Inferno-Gabriel-s-Inferno-1-by-Sylvain-Reynard.pdf
    • http://ieuicufioao.myhome.cx/3550553551555/Gabriel-39-s-Rapture-by-Sylvain-Reynard.pdf
    • http://ieuicufioao.myhome.cx/1557559556557559/Gabriel-s-Revenge-The-Adventures-of-Gabriel-Celtic-2-by-J-T-Lewis.pdf
    • http://ieuicufioao.myhome.cx/1558558552552557/The-Raven-The-Florentine-1-by-Sylvain-Reynard.pdf
    • http://ieuicufioao.myhome.cx/7550552556/The-Man-in-the-Black-Suit-by-Sylvain-Reynard.pdf
    • http://ieuicufioao.myhome.cx/2559552556558558/Gabriel-Garcia-Marquez-3-volume-set-Strange-Pilgrims-Love-in-the-Time-of-Cholera-One-Hundred-Years-of-Solitude-by-Gabriel-Garc-a-M-rquez.pdf
    • http://ieuicufioao.myhome.cx/4552559550557553/Hunt-Through-the-Cradle-of-Fear-Gabriel-Hunt-2-by-Gabriel-Hunt.pdf
    • http://ieuicufioao.myhome.cx/1551551557555552553/Gabriel-Garc-a-M-rquez-The-Last-Interview-and-Other-Conversations-The-Last-Interview-Series-by-Gabriel-Garc-a-M-rquez.pdf
    • http://ieuicufioao.myhome.cx/4552558559557558/Hunt-at-World-s-End-Gabriel-Hunt-3-by-Gabriel-Hunt.pdf
    • http://ieuicufioao.myhome.cx/4553551553552555/Hunt-at-the-Well-of-Eternity-Gabriel-Hunt-1-by-Gabriel-Hunt.pdf
    • http://ieuicufioao.myhome.cx/5557551555556557/Sirius-by-Gabriel-J-M-.pdf
    • http://ieuicufioao.myhome.cx/3557559555554551/The-Parisians-by-Marius-Gabriel.pdf
    • http://ieuicufioao.myhome.cx/1552557557558553/The-Nightghosts-Child-by-S-K-Gabriel.pdf
    • http://ieuicufioao.myhome.cx/4558551554555555/Gingerbread-by-Gabriel-Daemon.pdf
    • http://ieuicufioao.myhome.cx/2559555550559/South-Texas-by-Ann-Gabriel.pdf
    • http://ieuicufioao.myhome.cx/4555559559555559/Still-Waters-by-Alex-Gabriel.pdf
    • http://ieuicufioao.myhome.cx/3552559552556557/The-Martian-War-by-Gabriel-Mesta.pdf
    • http://ieuicufioao.myhome.cx/3555551558556553/Gabriel-by-Chris-Lange.pdf
    • http://ieuicufioao.myhome.cx/1551551557555552553/Gabriel-Garc-a-M-rquez-The-Last-Interview-and-Other-Conversations-The-Last-Interview-Series-by-Gabriel-Garc-a-M-rquez.pd