Malicious PDF — malware analysis report

Static analysis result for SHA-256 5480dc443c37aace…

MALICIOUS

PDF

22.7 KB Created: 2020-03-16 18:23:58 +00:00 Authoring application: mPDF 5.7
MD5: 6fffa08ae015a93e74e2b9f16f7657f0 SHA-1: 7859dce0f0aad9a899fcd1208dd4ce004d9f7161 SHA-256: 5480dc443c37aace4e95efee75cdf67c971f94fbdad92eb0d24050b5159d5a96
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be the hosting of a link farm, likely to redirect users to malicious content or for SEO poisoning. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/33d23d63d93d03d9/Solar-Defeated-Mythos-1-Oracle-of-Delphi-2-5-by-Diantha-Jones.pdf
    • http://tanceubio.myhome.cx/63d43d93d33d63d0/Indiana-Jones-and-the-Peril-at-Delphi-Indiana-Jones-Prequels-1-by-Rob-MacGregor.pdf
    • http://tanceubio.myhome.cx/13d13d13d43d73d63d4/Borland-Delphi-How-To-The-Definitive-Delphi-Problem-Solver-by-Gary-Frerking.pdf
    • http://tanceubio.myhome.cx/93d93d03d33d23d3/High-Seas-Cthulhu-Swashbuckling-Adventure-Meets-the-Mythos-by-William-Jones.pdf
    • http://tanceubio.myhome.cx/13d13d13d03d73d2/The-League-of-Delphi-The-Delphi-Trilogy-1-by-Chris-Everheart.pdf
    • http://tanceubio.myhome.cx/33d53d43d73d33d0/The-Delphi-Revolution-The-Delphi-Trilogy-3-by-Rysa-Walker.pdf
    • http://tanceubio.myhome.cx/63d43d13d63d53d5/Delphi-Complete-Works-of-Cicero-Illustrated-Delphi-Ancient-Classics-Book-23-by-Marcus-Tullius-Cicero.pdf
    • http://tanceubio.myhome.cx/73d73d23d43d33d9/Gods-amp-Titans-Oracle-Book-amp-Oracle-Set-by-Stacey-Demarco.pdf
    • http://tanceubio.myhome.cx/83d53d03d43d83d4/Delphi-Collected-Works-of-Lytton-Strachey-Illustrated-Delphi-Series-Seven-Book-15-by-Lytton-Strachey.pdf
    • http://tanceubio.myhome.cx/43d93d03d73d13d1/The-Oracle-s-Hatchling-The-Oracle-2-by-Mell-Eight.pdf
    • http://tanceubio.myhome.cx/93d83d53d23d63d4/The-Canterbury-Tales---Original-and-Modernised-Text-by-Geoffrey-Chaucer---Delphi-Classics-Illustrated-Delphi-Parts-Edition-Geoffrey-Chaucer-by-Geoffrey-Chaucer.pdf
    • http://tanceubio.myhome.cx/13d63d33d73d33d7/The-Solar-Queen-Solar-Queen-1-2-by-Andre-Norton.pdf
    • http://tanceubio.myhome.cx/93d83d53d43d23d9/The-Beautiful-and-Damned-by-F-Scott-Fitzgerald---Delphi-Classics-Illustrated-Delphi-Parts-Edition-F-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://tanceubio.myhome.cx/93d83d53d13d63d9/Les-Mis-rables-by-Victor-Hugo---Delphi-Classics-Illustrated-Delphi-Parts-Edition-Victor-Hugo-by-Victor-Hugo.pdf
    • http://tanceubio.myhome.cx/43d33d43d83d33d6/Despondency-The-Story-of-a-Defeated-Man-by-Paul-A-Wunderlich.pdf
    • http://tanceubio.myhome.cx/83d63d03d63d93d8/Stalingrad-The-City-that-Defeated-the-Third-Reich-by-Jochen-Hellbeck.pdf
    • http://tanceubio.myhome.cx/33d83d33d53d63d5/Pacific-Fury-How-Australia-and-Her-Allies-Defeated-the-Japanese-by-Peter-Thompson.pdf
    • http://tanceubio.myhome.cx/13d03d13d23d23d43d9/Tor-and-the-Deep-Web-Bitcoin-DarkNet-amp-Cryptocurrency-2-in-1-Book-2017-18-NSA-Spying-Defeated-by-Lance-Henderson.pdf
    • http://tanceubio.myhome.cx/93d73d03d63d43d7/The-Defeated-Aristocrat-Konigsberg-1919-Konigsberg-series-by-Katherine-John.pdf
    • http://tanceubio.myhome.cx/13d83d53d73d03d2/Sauron-Defeated-The-History-of-The-Lord-of-the-Rings-Part-Four-The-History-of-Middle-Earth-9-by-J-R-R-Tolkien.pdf
    • http://tanceubio.myhome.cx/63d43d13d63d53d5/Delphi-Complete-Works-of-Cicero-Illustrated-Delphi-Ancient-Classics-Book-23-by-Marcus-Tullius-Cicero