Malicious PDF — malware analysis report

Static analysis result for SHA-256 483fcd675da38e84…

MALICIOUS

PDF

28.4 KB Created: 2020-03-18 18:09:02 +00:00 Authoring application: mPDF 5.7
MD5: e3cce0e405ba0328520515ba538182bb SHA-1: b9b7d1b65ec452d3448059766d624aad1031b54d SHA-256: 483fcd675da38e84346e4415fdd9a9357cdd34aef95d648e16cda2bdd3ef071d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external websites, identified by the PDF_SEO_LINK_FARM heuristic. ClamAV also detected this file as Pdf.Dropper.Agent-7766010-0, indicating a malicious dropper. The primary function appears to be redirecting users to a network of sites hosted on weisncio.myhome.cx, likely for malicious purposes such as phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7766010-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7766010-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/5628622624621626/Paris-A-World-Heritage-Site-Travel-Guide-Paris-Banks-of-the-Seine---2017-by-J-r-me-Sabatier.pdf
    • http://weisncio.myhome.cx/1621620623624628622/Untersuchungen-Uber-Das-Phanomen-Der-Erdbeben-in-Der-Schweiz-Vol-2-Seine-Geschichte-Seine-Ausserungsweise-Seinen-Zusammenhang-Mit-Anderen-Phanomenen-Und-Mit-Den-Petrographischen-Und-Geotektonischen-Werhaltnissen-Des-Bodens-Und-Seine-Bedeutung-F-by-Georg-Heinrich-Otto-Volger.pdf
    • http://weisncio.myhome.cx/1620626620625620626/Sport-Paris-Fussballverein-Aus-Paris-Sportstatte-in-Paris-Sportveranstaltung-in-Paris-Sportverein-Paris-Olympische-Sommerspiele-1900-by-Quelle-Wikipedia.pdf
    • http://weisncio.myhome.cx/4624625622629626/My-Paris-Dream-An-Education-in-Style-Slang-and-Seduction-in-the-Great-City-on-the-Seine-by-Kate-Betts.pdf
    • http://weisncio.myhome.cx/2624624625620624/Paris-by-Edward-Rutherfurd.pdf
    • http://weisncio.myhome.cx/1625620628621625/Death-in-Paris-1795-1801-The-Records-of-the-Basse-Geole-de-La-Seine-Vendemiaire-Year-IV-Fructidor-Year-IX-by-Richard-Cobb.pdf
    • http://weisncio.myhome.cx/1620626620622624621/Paris-Roman-einer-Stadt-by-Edward-Rutherfurd.pdf
    • http://weisncio.myhome.cx/1620623621629621623/MENSCHENBLUT-steigert-seine-blanke-Wut-Ein-Psychokiller-treibt-seine-Opfer-bestialisch-in-den-Tod-by-Paul-Rheinfels.pdf
    • http://weisncio.myhome.cx/3620625629628/Paris-My-Sweet-by-Amy-Thomas.pdf
    • http://weisncio.myhome.cx/1620629626623621628/Wissenschaft-Paris-Bildung-in-Paris-Forschung-in-Paris-Institut-de-France-Foucaultsches-Pendel-Academie-Francaise-by-Quelle-Wikipedia.pdf
    • http://weisncio.myhome.cx/4621625624624623/Americans-Bombing-Paris-by-Thomas-Bartlett.pdf
    • http://weisncio.myhome.cx/6622621625626625/To-Havre-and-Have-Not-by-Randy-Russell.pdf
    • http://weisncio.myhome.cx/6622621626621622/Le-Havre-New-York-by-Christian-Cleres.pdf
    • http://weisncio.myhome.cx/8628620628627/A-Flame-in-Sunlight-The-Life-and-Work-of-Thomas-de-Quincey-by-Edward-Sackville-West.pdf
    • http://weisncio.myhome.cx/6622621625626620/Havre-de-Grace-Then-and-Now-Maryland-by-Linda-Noll.pdf
    • http://weisncio.myhome.cx/7629622620627620/Le-Havre-Auguste-Perret-Et-La-Reconstruction-by-Claire-Etienne.pdf
    • http://weisncio.myhome.cx/9622624626629626/Aufgaben-Und-Probleme-Des-Instituts-Fur-Kohleforschung-in-Frankreich-Anforderungen-an-Den-Wissenschaftlichen-Nachwuchs-in-Der-Forschung-Und-Seine-Ausbildung-Das-Institut-Fur-Eisenforschung-in-Frankreich-Und-Seine-Probleme-in-Der-Eisenforschung-by-Raymond-Cheradame.pdf
    • http://weisncio.myhome.cx/9628628622623/Old-Man-from-the-Repple-Depple-The-Story-of-an-Infantry-Replacement-Soldier-in-Europe-in-World-War-II-by-Thomas-Edward-Oblinger.pdf
    • http://weisncio.myhome.cx/6622621625626622/Havre-de-Grace-in-the-War-of-1812-Fire-on-the-Chesapeake-by-Heidi-Glatfelter.pdf
    • http://weisncio.myhome.cx/6622628626623623/The-Paris-Game-Charles-de-Gaulle-the-Liberation-of-Paris-and-the-Gamble-that-Won-France-by-Ray-Argyle.pdf
    • http://weisncio.myhome.cx/4624625622629626/My-Paris-Dream-An-Education-in-Style-Slang-and-Seduction-in-the-Great-City-on-the-Seine-by-K