Malicious PDF — malware analysis report

Static analysis result for SHA-256 5a31134bb28eb5a0…

MALICIOUS

PDF

12.7 KB Created: 2020-03-19 02:37:38 +00:00 Authoring application: mPDF 5.7
MD5: 43bd9a5da904d3de013ab6c19bb8e20a SHA-1: d96175ab8aec1f690e4130a028dc0d3055fc4297 SHA-256: 5a31134bb28eb5a082e24d3cefb4841be588df10f925e0281ea5f559b74cbfc8
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'weisncio.myhome.cx'. This pattern is indicative of SEO poisoning or a distribution mechanism for further malicious content. While no scripts were explicitly extracted, the 'EMBEDDED_URL' heuristic and the nature of the links suggest potential for JavaScript execution or other document-based exploits to redirect users. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8905

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/2628629625625620/Smile-Smile-1-by-Raina-Telgemeier.pdf
    • http://weisncio.myhome.cx/2625622625627629/Smile-by-Raina-Telgemeier.pdf
    • http://weisncio.myhome.cx/4624620625620/Kristy-s-Great-Idea-Baby-Sitters-Club-Graphic-Novels-1-by-Raina-Telgemeier.pdf
    • http://weisncio.myhome.cx/3626621629624626/Archaic-Smile-by-A-E-Stallings.pdf
    • http://weisncio.myhome.cx/1627621620624629/Mason-s-Smile-by-Kat-Barrett.pdf
    • http://weisncio.myhome.cx/8628627629627/The-Smile-by-Donna-Jo-Napoli.pdf
    • http://weisncio.myhome.cx/2627620622623621/See-You-Smile-by-Dawn-Sister.pdf
    • http://weisncio.myhome.cx/4624626622620622/The-Shadow-of-Your-Smile-by-Susan-May-Warren.pdf
    • http://weisncio.myhome.cx/5626626623625/Secret-Smile-by-Nicci-French.pdf
    • http://weisncio.myhome.cx/3626623629624628/Smile-of-Truth-by-Gori-Suture.pdf
    • http://weisncio.myhome.cx/1623627623625626/The-Eternal-Smile-Three-Stories-by-P-r-Lagerkvist.pdf
    • http://weisncio.myhome.cx/2625621624624622/In-a-Moon-Smile-by-Sherri-Coner.pdf
    • http://weisncio.myhome.cx/9627628622/A-Smile-in-One-Eye-a-Tear-in-the-Other-by-Ralph-Webster.pdf
    • http://weisncio.myhome.cx/3620620623622627/A-Smile-in-His-Lifetime-by-Joseph-Hansen.pdf
    • http://weisncio.myhome.cx/1621627629627620620/The-Gioconda-Smile-by-Aldous-Huxley.pdf
    • http://weisncio.myhome.cx/1621625627627629627/Life-with-a-Smile-by-Wynette-Bryant.pdf
    • http://weisncio.myhome.cx/2621621627622624/Sunlit-Smile-by-Renee-Leigh.pdf
    • http://weisncio.myhome.cx/4621626624624623/Augustus-and-His-Smile-by-Catherine-Rayner.pdf
    • http://weisncio.myhome.cx/3622620620628625/That-One-May-Smile-Garda-West-1-by-Valerie-Keogh.pdf
    • http://weisncio.myhome.cx/7620620621629/The-Traitor-s-Smile-Pimpernelles-2-by-Patricia-Elliott.pdf