Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f48e82430753975…

MALICIOUS

PDF

18.3 KB Created: 2020-02-10 13:03:20 +00:00 Authoring application: mPDF 5.7
MD5: da3fe6718512ab8f940be397713ae4af SHA-1: 5e308494b0a5463687f44276c4a486b54ed31734 SHA-256: 5f48e82430753975428c10401c4f368a5a4b65c1de615085cb6c43f80fa589ac
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was detected as malicious by ClamAV and an ML classifier, and exhibits characteristics of a link farm. It contains a large number of embedded URLs pointing to external PDF files, suggesting a potential distribution or redirection mechanism. While no scripts were explicitly extracted, the presence of embedded URLs and the nature of the heuristic firings indicate a likely attempt to lure users to malicious content or facilitate further compromise, possibly via spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7865751-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7865751-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/5550551553551551/Three-Wishes-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/3556554559553553/Got-Your-Number-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/5550551556559558/Stop-the-Wedding-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/3555553554554550/Stop-the-Wedding-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/3559550555559551/My-Favorite-Mistake-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/2551557552551555/Baby-Don-t-Go-Southern-Roads-3-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/1557552553553556/Baby-Come-Home-Southern-Roads-2-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/1554558552559553/2-Bodies-for-the-Price-of-1-Body-Movers-2-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/2557550557555550/6-Killer-Bodies-Body-Movers-6-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/1550550555558554/Sleep-Thieves-an-Eye-Opening-Exploration-into-the-Science-and-Mysteries-of-Sleep-by-Stanley-Coren.pdf
    • http://ieuicufioao.myhome.cx/8551559556557559/Sleep-It-Does-A-Family-Good-How-Busy-Families-Can-Overcome-Sleep-Deprivation-by-Archibald-D-Hart.pdf
    • http://ieuicufioao.myhome.cx/6550550559557556/Sleep-Smarter-21-Essential-Strategies-to-Sleep-Your-Way-to-A-Better-Body-Better-Health-and-Bigger-Success-by-Shawn-Stevenson.pdf
    • http://ieuicufioao.myhome.cx/8557550552552553/Sleep-Smarter-21-Essential-Strategies-to-Sleep-Your-Way-to-a-Better-Body-Better-Health-and-Bigger-Success-by-Shawn-Stevenson.pdf
    • http://ieuicufioao.myhome.cx/6555559554/Why-We-Sleep-Unlocking-the-Power-of-Sleep-and-Dreams-by-Matthew-Walker.pdf
    • http://ieuicufioao.myhome.cx/1550559555556550558/Holistic-Approach-to-Sleep-and-Sleep-Disorders-by-Celia-Ebrahimi.pdf
    • http://ieuicufioao.myhome.cx/4557550556550559/His-Baby-Bond-Sacred-Bond-1-by-Lee-Tobin-McClain.pdf
    • http://ieuicufioao.myhome.cx/3554554557554557/Secret-Bond-Jamie-Bond-2-by-Gemma-Halliday.pdf
    • http://ieuicufioao.myhome.cx/1554558553551553/Body-Movers-Body-Movers-1-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/3557556551556559/Two-Guys-Detective-Agency-Two-Guys-Detective-Agency-1-by-Stephanie-Bond.pdf
    • http://ieuicufioao.myhome.cx/4550559555555552/Classic-Ruskin-Bond-Complete-amp-Unabridged-by-Ruskin-Bond.pdf