Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c99d7de0cfee6b9…

MALICIOUS

PDF

20.7 KB Created: 2020-03-14 00:54:50 +00:00 Authoring application: mPDF 5.7
MD5: 688bc65cbb29886bc0ca8f8e4dc7c0b3 SHA-1: 31ba939348a9e1e1867fa863ba1ed53f5513267f SHA-256: 5c99d7de0cfee6b9a2864b2ff60f3f9d82ff73d6dc0805989b0c501479ddf01c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF documents. These links are likely part of a link farm designed to manipulate search engine rankings or distribute spam. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/3622624623625624/London-A-Travel-Guide-Through-Time-by-Matthew-Green.pdf
    • http://weisncio.myhome.cx/3624620621627621/A-Travel-Guide-to-Shakespeare-s-London-by-James-Barter.pdf
    • http://weisncio.myhome.cx/8625621628627625/The-Ultimate-Green-Tea-Guide-History-Green-Tea-Benefits-Green-Tea-Types-Best-Brewing-Practices-and-Tasty-Green-Tea-Recipes-for-Everyone-by-Ayumi-Furuya.pdf
    • http://weisncio.myhome.cx/4621620620629626/A-Time-Travel-Fantasy-Bundle-Footsteps-in-Time-Prince-of-Time-After-Cilmeri-1-2-by-Sarah-Woodbury.pdf
    • http://weisncio.myhome.cx/4624625628629622/The-Big-Book-Of-Time-Travel-Romance-Includes-After-Cilmeri-0-5-Lost-Highlander-1-The-McKinnon-Legends-1-Out-of-Time-1-Time-Walkers-1-by-Sarah-Woodbury.pdf
    • http://weisncio.myhome.cx/1620626629622627/Time-For-Eternity-Da-Vinci-Time-Travel-2-by-Susan-Squires.pdf
    • http://weisncio.myhome.cx/2622620622629627/Time-Enough-for-Love-Italian-Time-Travel-2-by-Morgan-O-39-Neill.pdf
    • http://weisncio.myhome.cx/3622624621622621/London-s-Hidden-Rivers-A-walker-s-guide-to-the-subterranean-waterways-of-London-by-David-Fathers.pdf
    • http://weisncio.myhome.cx/2621622625625629/Time-Held-Me-Green-and-Dying-Ant-and-Cleo-7-by-Dominic-Green.pdf
    • http://weisncio.myhome.cx/3622621629628621/Out-of-Time---Five-Tales-of-Time-Travel-by-Janet-Guy.pdf
    • http://weisncio.myhome.cx/2626622620626620/Out-of-Time-A-Time-Travel-Novel-by-Cliff-Ball.pdf
    • http://weisncio.myhome.cx/2623628627621624/London-Under-London-A-Subterranean-Guide-by-Richard-Trench.pdf
    • http://weisncio.myhome.cx/3622623621629625/The-Life-of-London-4-Volume-Set-Elizabeth-s-London-Dr-Johnson-s-London-Restoration-London-and-Victorian-London-by-Liza-Picard.pdf
    • http://weisncio.myhome.cx/6625625624622620/The-Spleen-And-Other-Poems-by-Matthew-Green.pdf
    • http://weisncio.myhome.cx/1626621625620623/The-Ghosts-Who-Travel-with-Me-A-Literary-Pilgrimage-Through-Brautigan-s-America-by-Allison-Green.pdf
    • http://weisncio.myhome.cx/5620626622626627/The-Wizard-of-the-Nile-The-Hunt-for-Africa-s-Most-Wanted-by-Matthew-Green.pdf
    • http://weisncio.myhome.cx/1624623626622622/The-Man-Who-Made-Time-Travel-by-Kathryn-Lasky.pdf
    • http://weisncio.myhome.cx/4626624625625627/How-to-Travel-Full-Time-by-Colin-Wright.pdf
    • http://weisncio.myhome.cx/3627627622628627/To-Say-Nothing-of-the-Dog-Oxford-Time-Travel-2-by-Connie-Willis.pdf
    • http://weisncio.myhome.cx/2624625622627/To-Say-Nothing-of-the-Dog-Oxford-Time-Travel-2-by-Connie-Willis.pdf