Malicious PDF — malware analysis report

Static analysis result for SHA-256 528d020d8885d406…

MALICIOUS

PDF

25.9 KB Created: 2020-03-18 16:32:50 +00:00 Authoring application: mPDF 5.7
MD5: b75c19cd5c53755c8b042ae52003c666 SHA-1: 07038283eb07fea13e75f65541a98b009aecf3e1 SHA-256: 528d020d8885d4063ba1fbb36357fe2e4bf9120c0377c1e71dfdce897dcf03e4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links, such as http://laoieoa.myhome.cx/2c05c05c02c03c00/Battle-at-Bull-Run-A-History-of-the-First-Major-Campaign-of-the-Civil-War-by-William-C-Davis.pdf, likely lead to malicious content or phishing sites. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/2c05c05c02c03c00/Battle-at-Bull-Run-A-History-of-the-First-Major-Campaign-of-the-Civil-War-by-William-C-Davis.pdf
    • http://laoieoa.myhome.cx/2c05c04c06c08c05/Return-to-Bull-Run-The-Campaign-and-Battle-of-Second-Manassas-by-John-J-Hennessy.pdf
    • http://laoieoa.myhome.cx/8c07c06c09c08c00/The-Russo-Japanese-War-Illustrated-Edition-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-of-the-Japan-Sea-Peace-Treaty-by-Sydney-Tyler.pdf
    • http://laoieoa.myhome.cx/2c05c04c08c05c07/Epic-Battles-of-the-Civil-War-Volume-1-Bull-Run-by-William-Messner-Loebs.pdf
    • http://laoieoa.myhome.cx/2c05c05c04c06c08/The-Battle-of-New-Market-by-William-C-Davis.pdf
    • http://laoieoa.myhome.cx/9c01c08c00c02/The-March-on-Washington-Jobs-Freedom-and-the-Forgotten-History-of-Civil-Rights-by-William-P-Jones.pdf
    • http://laoieoa.myhome.cx/6c04c06c05c03c02/A-History-of-France-from-the-Earliest-Times-to-the-Treaty-of-Versailles-by-William-Stearns-Davis.pdf
    • http://laoieoa.myhome.cx/1c00c05c02c00/The-Last-Stand-Custer-Sitting-Bull-and-the-Battle-of-the-Little-Bighorn-by-Nathaniel-Philbrick.pdf
    • http://laoieoa.myhome.cx/2c05c02c06c09c05/We-Are-Not-Afraid-The-Story-of-Goodman-Schwerner-and-Chaney-and-the-Civil-Rights-Campaign-for-Mississippi-by-Seth-Cagin.pdf
    • http://laoieoa.myhome.cx/3c08c05c02c09c01/The-Gleam-of-Bayonets-The-Battle-of-Antietam-and-Robert-E-Lee-s-Maryland-Campaign-September-1862-by-James-V-Murfin.pdf
    • http://laoieoa.myhome.cx/5c01c00c09c06c02/Jefferson-Davis-The-Man-and-His-Hour-by-William-C-Davis.pdf
    • http://laoieoa.myhome.cx/4c08c01c01c06/A-Separate-Battle-Women-and-the-Civil-War-by-Ina-Chang.pdf
    • http://laoieoa.myhome.cx/5c01c00c02c01c02/The-Campaign-for-Atlanta-by-William-R-Scaife.pdf
    • http://laoieoa.myhome.cx/8c06c00c02c05c09/Louisa-May-s-Battle-How-the-Civil-War-Led-to-Little-Women-by-Kathleen-Krull.pdf
    • http://laoieoa.myhome.cx/2c02c03c06c04c03/Under-Siege-Three-Children-at-the-Civil-War-Battle-for-Vicksburg-by-Andrea-Warren.pdf
    • http://laoieoa.myhome.cx/2c03c08c04c07c07/The-Battle-for-Spain-The-Spanish-Civil-War-1936-1939-by-Antony-Beevor.pdf
    • http://laoieoa.myhome.cx/2c05c00c06c00c09/The-Bill-of-the-Century-The-Epic-Battle-for-the-Civil-Rights-Act-by-Clay-Risen.pdf
    • http://laoieoa.myhome.cx/2c05c05c02c08c01/The-Maps-of-Antietam-An-Atlas-of-The-Antietam-Sharpsburg-Campaign-Including-the-Battle-of-South-Mountain-September-2---20-1862-by-Bradley-M-Gottfried.pdf
    • http://laoieoa.myhome.cx/4c02c01c01c00c09/Three-Roads-to-the-Alamo-The-Lives-and-Fortunes-of-David-Crockett-James-Bowie-and-William-Barret-Travis-by-William-C-Davis.pdf
    • http://laoieoa.myhome.cx/8c02c00c04c05c09/Bull-A-History-of-the-Boom-and-Bust-1982-2004-by-Maggie-Mahar.pdf
    • http://laoieoa.myhome.cx/8c07c06c09c08c00/The-Russo-Japanese-War-Illustrated-Edition-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-of-the-Japan-Sea-Peace-Treaty