Malicious PDF — malware analysis report

Static analysis result for SHA-256 4c7a97751bd4bddd…

MALICIOUS

PDF

18.0 KB Created: 2020-02-10 14:34:20 +00:00 Authoring application: mPDF 5.7
MD5: 2156b8d6e844b84376308a945df7bc0f SHA-1: 7529762ffaf056ef0a3578b3d7bb5a6e2b5fb9fe SHA-256: 4c7a97751bd4bddd97080057cdf53b4410519cdcdfcde61285b31a67ce1d19ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'weisncio.myhome.cx'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/7621624626621621/Les-Mis-rables-En-Fran-ais-Contemporain-Et-En-Anglais-The-Poor-in-Contemporary-French-and-English-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/9628625621626629/Les-Mis-rables-by-Victor-Hugo---Delphi-Classics-Illustrated-Delphi-Parts-Edition-Victor-Hugo-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/7625626620628623/Les-Mis-rables-By-Victor-Hugo---Illustrated-Free-Audiobook-Unabridged-Original-E-Reader-Friendly-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/6629620628623629/Profil---Hugo-Victor-Le-Dernier-jour-d-un-condamn-Analyse-litt-raire-de-l-oeuvre-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/7625627626620623/The-Works-of-Victor-Hugo-Hans-of-Iceland-Bug-Jargal-Claude-Gueux-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/7625627627626626/The-Works-of-Victor-Hugo-Hans-of-Iceland-Translated-by-H-Smith-Bug-Jargal-Last-Day-of-a-Condemned-Man-Claude-Gueux-Translated-by-A-Ward-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/5625625621620620/Victor-Hugo-s-The-Hunchback-Of-Nortre-Dame-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/9626624627620622/Victor-Hugo-quot-Die-Elenden-Les-Mis-rables-quot-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/5622626629623623/The-Memoirs-of-Victor-Hugo-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/5628624629628626/Les-Mis-rables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/6624628628623620/Les-Mis-rables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/8621627623627622/Les-Miserables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/4624626622622620/Les-Mis-rables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/4628625629626/The-Toilers-of-the-Sea-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/2625628629621623/Les-Mis-rables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/6621629629629623/Les-Miserables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/5623622624626623/Les-Miserables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/4624621627626626/Ninety-Three-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/3622620628621/Les-Mis-rables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/5625622627620627/Les-Mis-rables-by-Victor-Hugo.pdf
    • http://weisncio.myhome.cx/6629620628623629/Profil---Hugo-Victor-Le-Dernier-jour-d-u