Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a80b15e1e74be84…

MALICIOUS

PDF

22.6 KB Created: 2020-03-18 18:09:00 +00:00 Authoring application: mPDF 5.7
MD5: ed7a6fc9f47e54d4d89b0b740749d4bb SHA-1: f00f82ee6fe8fe6de608622a6d86508168359087 SHA-256: 4a80b15e1e74be846b372a1a7e380ab482aa76be2ff20ddc2ed86fd61f447c5f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDFs hosted on the domain 'weisncio.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/5629625622623626/Strange-Case-Of-Dr-Jekyll-And-Mr-Hyde-And-Dracula-Color-Illustrated-Formatted-for-E-Readers-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/8622629624624622/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-Lo-strano-caso-del-dottor-Jekyll-e-del-signor-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/5629620623626625/Strange-Case-of-Dr-Jekyll-And-Mr-Hyde---Le-cas-trange-du-Dr-Jekyll-et-de-M-Hyde-Texte-int-gral-anglais-avec-traduction-fran-aise-de-Th-o-Varlet-en-regard-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/7622628622629625/Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/4622626624624621/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/2623621626622626/Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/5625622626626628/Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/1620628623627625628/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/3621623627626620/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/5626621629622625/Strange-Case-of-Dr-Jekyll-and-MR-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/1620620626621629622/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/8625624620621626/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/1620621629625623628/The-Strange-Case-of-Dr-Jekyll-amp-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/2623627624623625/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-and-Other-Stories-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/8620622629627625/Treasure-Island-Color-Illustrated-Formatted-for-E-Readers-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/6622629626627/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-and-Other-Tales-of-Terror-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/9621621624621623/The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-The-100-Greatest-Books-Ever-Written-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/4627624625629629/The-Strange-Case-of-Dr-Jekyll-amp-Mr-Hyde-amp-Other-Tales-Kidnapped-Treasure-Island-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/6629628625620620/The-Novels-of-R-L-Stevenson-Complete-Collection-13-Novels---Treasure-Island-The-Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-The-Black-Arrow-of-Ballantrae-The-Wrong-Box-and-others-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome.cx/7621620627620624/The-Strange-Case-of-Dr-Jeckyll-and-Mr-Hyde-by-Robert-Louis-Stevenson.pdf
    • http://weisncio.myhome