Malicious PDF — malware analysis report

Static analysis result for SHA-256 5da8906c09185dcf…

MALICIOUS

PDF

19.8 KB Created: 2020-03-12 02:16:56 +00:00 Authoring application: mPDF 5.7
MD5: d5edafa17b27ff8ec77bc7f30a216205 SHA-1: 3de3b01ae8a90465e620b765234ead829b2330ef SHA-256: 5da8906c09185dcf23f4e42dea2f2f492c3b450745b9966eb392e6b353c81632
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the 'weisncio.myhome.cx' domain, suggesting a link farm or content redirection scheme. While no scripts were explicitly extracted, the presence of embedded URLs within a PDF is often used to redirect users to malicious sites or to download further payloads, aligning with T1059.007 if JavaScript were involved in the redirection, and T1566.001 as a potential delivery vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1621629620627620621/Babbitt-By-Sinclair-Lewis-Illustrated-FREE-The-Man-Who-Was-Thursday-by-Sinclair-Lewis.pdf
    • http://weisncio.myhome.cx/9628622624628625/Babbitt-by-Sinclair-Lewis.pdf
    • http://weisncio.myhome.cx/3624628628629621/Babbitt-by-Sinclair-Lewis.pdf
    • http://weisncio.myhome.cx/5620621623626625/Free-Air-by-Sinclair-Lewis.pdf
    • http://weisncio.myhome.cx/4621624622625/It-Can-t-Happen-Here-by-Sinclair-Lewis.pdf
    • http://weisncio.myhome.cx/3624625628622628/Arrowsmith-by-Sinclair-Lewis.pdf
    • http://weisncio.myhome.cx/7622621624626629/Alice-in-Wonderland-And-Through-The-Looking-Glass-By-Lewis-Carroll---Illustrated-Free-Audiobook-Unabridged-Original-E-Reader-Friendly-by-Lewis-Carroll.pdf
    • http://weisncio.myhome.cx/5624621620622622/Alice-s-Adventures-in-Wonderland-By-Lewis-Carroll---Illustrated-Comes-with-a-Free-Audiobook-by-Lewis-Carroll.pdf
    • http://weisncio.myhome.cx/7621623622622624/Alice-in-Wonderland-And-Through-The-Looking-Glass-By-Lewis-Carroll-amp-Illustrated-An-Audiobook-Free-by-Lewis-Carroll.pdf
    • http://weisncio.myhome.cx/7622626620627624/The-Post-Mortem-Murder-by-Sinclair-Lewis.pdf
    • http://weisncio.myhome.cx/5622629629624626/Alice-in-Wonderland-Illustrated-plus-FREE-Audiobook-by-Lewis-Carroll.pdf
    • http://weisncio.myhome.cx/1621628626624629629/Alle-wollten-ihn-zertreten-Luke-Sinclair-Western-Band-29-by-Luke-Sinclair.pdf
    • http://weisncio.myhome.cx/1620623624623628623/Das-M-dchen-und-der-Deserteur-Luke-Sinclair-Western-Band-27-by-Luke-Sinclair.pdf
    • http://weisncio.myhome.cx/2622620622629628/The-Devil-of-Clan-Sinclair-Clan-Sinclair-1-by-Karen-Ranney.pdf
    • http://weisncio.myhome.cx/4623624624622626/The-Against-Taffy-Sinclair-Club-Taffy-Sinclair-1-by-Betsy-Haynes.pdf
    • http://weisncio.myhome.cx/5626621628627620/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll-with-an-excerpt-from-The-Life-and-Letters-of-Lewis-Carroll-by-Lewis-Carroll.pdf
    • http://weisncio.myhome.cx/4623620620625624/The-Complete-Illustrated-Works-by-Lewis-Carroll.pdf
    • http://weisncio.myhome.cx/8628623623628622/The-Collected-Letters-of-C-S-Lewis-Volume-3-Narnia-Cambridge-and-Joy-1950---1963-by-C-S-Lewis.pdf
    • http://weisncio.myhome.cx/1622629629626624/The-C-S-Lewis-Index-A-Comprehensive-Guide-to-Lewis-s-Writings-and-Ideas-by-Janine-Goffar.pdf
    • http://weisncio.myhome.cx/8629621624625/A-Year-with-C-S-Lewis-Daily-Readings-from-His-Classic-Works-by-C-S-Lewis.pdf