Malicious PDF — malware analysis report

Static analysis result for SHA-256 581b68840d2f19a3…

MALICIOUS

PDF

21.5 KB Created: 2020-03-20 02:11:07 +00:00 Authoring application: mPDF 5.7
MD5: 02e31553b7763c51c02f708dc6f79486 SHA-1: 67365b85213829773eab6e91b985bf74e253d9d2 SHA-256: 581b68840d2f19a3da0a1799f3d692cf990bf672720ef71ab3433eaed131015a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents on the domain 'laoieoa.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/2c03c04c01c02c07/Opportunity-Knocks-Laissez-Faire-1-by-L-D-Blakeley.pdf
    • http://laoieoa.myhome.cx/7c00c09c00c03c07/La-econom-a-en-una-lecci-n-Laissez-Faire-by-Henry-Hazlitt.pdf
    • http://laoieoa.myhome.cx/1c09c02c06c07c07/Capitalist-Manifesto-The-Historic-Economic-and-Philosophic-Case-for-Laissez-Faire-by-Andrew-Bernstein.pdf
    • http://laoieoa.myhome.cx/7c00c09c00c04c01/Queen-of-the-Faire-The-Faire-Folk-Saga-7-by-Gillian-Summers.pdf
    • http://laoieoa.myhome.cx/5c00c00c09c01c07/The-Power-of-Peppermint-by-L-D-Blakeley.pdf
    • http://laoieoa.myhome.cx/9c04c09c03c09c05/The-School-of-Shakspere-Histrio-Mastix-Or-the-Player-Whipt-the-Prodigal-Son-Jacke-Drums-Entertainement-a-Warning-for-Faire-Women-Faire-Em-the-Miller-s-Daughter-of-Manchester-an-Account-of-Robert-Greene-His-Life-and-Works-and-His-Attacks-on-Sha-by-Frederick-James-Furnivall.pdf
    • http://laoieoa.myhome.cx/8c03c06c04c01c09/L-art-de-bien-faire-l-amour-L-art-de-faire-l-amour-expliqu-sans-tabou-et-sans-vulgarit-aucune-by-G-rard-Leleu.pdf
    • http://laoieoa.myhome.cx/5c00c02c09c05/Life-Knocks-by-Craig-Stone.pdf
    • http://laoieoa.myhome.cx/3c01c09c03c06c08/The-Zombie-Always-Knocks-Twice-Hollyweird-1-by-E-Van-Lowe.pdf
    • http://laoieoa.myhome.cx/2c04c02c04c01c02/Hard-Knocks-Charlie-Fox-3-by-Zo-Sharp.pdf
    • http://laoieoa.myhome.cx/4c00c00c01c04c02/The-School-of-Hard-Knocks-Schooled-in-Magic-5-by-Christopher-G-Nuttall.pdf
    • http://laoieoa.myhome.cx/6c03c02c08c06c03/Toute-la-fonction-Assistante---Savoirs-Savoir-faire-Savoir--tre-Savoirs-Savoir-faire-Savoir--tre-by-Christine-Harache.pdf
    • http://laoieoa.myhome.cx/2c02c07c07c05/ReBecoming-The-Way-of-Opportunity-by-J-R-Maxon.pdf
    • http://laoieoa.myhome.cx/9c06c04c02c03/Gates-of-Time-Windows-of-Opportunity-by-A-.pdf
    • http://laoieoa.myhome.cx/3c08c04c00c09c02/Target-of-Opportunity-by-Justine-Davis.pdf
    • http://laoieoa.myhome.cx/4c00c00c05c04c04/Windows-Of-Opportunity-by-Sherri-Cortland.pdf
    • http://laoieoa.myhome.cx/4c04c06c08c09c08/Raffles-and-the-Golden-Opportunity-by-Victoria-Glendinning.pdf
    • http://laoieoa.myhome.cx/2c01c01c08c06c07/Motive-Means-and-Opportunity-by-Louis-H-Campbell.pdf
    • http://laoieoa.myhome.cx/7c09c04c07c01c09/Age-of-Opportunity-Lessons-from-the-New-Science-of-Adolescence-by-Laurence-Steinberg.pdf
    • http://laoieoa.myhome.cx/2c08c07c00c09c05/Glad-No-Matter-What-Transforming-Loss-and-Change-into-Gift-and-Opportunity-by-S-A-R-K-.pdf
    • http://laoieoa.myhome.cx/8c03c06c04c01c09/L-art-de-bien-faire-l-amour-L-art-de-faire-l-amour-expliqu-sans-t