Malicious PDF — malware analysis report

Static analysis result for SHA-256 6280501475be787f…

MALICIOUS

PDF

22.7 KB Created: 2020-03-18 23:42:55 +00:00 Authoring application: mPDF 5.7
MD5: 563233d33f07b26ee839956efc792d90 SHA-1: b5d1d95b897d06a14401abc80bb18035c0b4dd09 SHA-256: 6280501475be787fed7ff31145cdab102272e19ffc8998ce172cc02282a920bc
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, masquerading as a link farm for book PDFs. The primary heuristic indicates this is a SEO link farm, suggesting a malicious intent to drive traffic or distribute further malware. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://peldoaio.myhome.cx/23d63d93d93d23d0/Buffy-Cazavampiros-Inmortal-Buffy-the-Vampire-Slayer-Season-3-9-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/43d33d73d93d23d2/Buffy-the-Vampire-Slayer-Oz-Buffy-the-Vampire-Slayer-Comic-20-Buffy-Season-4-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/43d43d33d73d83d6/Buffy-the-Vampire-Slayer-Remaining-Sunlight-Buffy-the-Vampire-Slayer-Comic-11-Buffy-Season-3-by-Andi-Watson.pdf
    • http://peldoaio.myhome.cx/43d33d83d03d83d0/Monster-Island-Buffy-the-Vampire-Slayer-Season-6-2-Angel-Season-3-4-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/73d63d33d63d63d3/Les-fautes-du-p-re-Buffy-the-Vampire-Slayer-Season-3-1-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/23d73d03d53d23d0/Buffy-Cazavampiros-El-Libro-de-los-Cuatros-Buffy-the-Vampire-Slayer-Novelas-by-Nancy-Holder.pdf
    • http://peldoaio.myhome.cx/43d03d33d63d53d5/Buffy-the-Vampire-Slayer-Vol-3-BTVS-Collection-3-by-Christopher-Golden.pdf
    • http://peldoaio.myhome.cx/33d03d63d13d03d5/Buffy-the-Vampire-Slayer-Billy-the-Vampire-Slayer-Part-1-Season-9-14-by-Jane-Espenson.pdf
    • http://peldoaio.myhome.cx/13d03d23d13d03d33d8/Buffy-The-Vampire-Slayer-Staffel-8-Bd-2-Wie-t-tet-man-eine-J-gerin-Buffy-the-Vampire-Slayer---Staffel-8-by-Joss-Whedon.pdf
    • http://peldoaio.myhome.cx/53d63d63d83d73d3/Why-Buffy-Matters-The-Art-of-Buffy-the-Vampire-Slayer-by-Rhonda-V-Wilcox.pdf
    • http://peldoaio.myhome.cx/13d03d23d13d23d13d7/Buffy-the-Vampire-Slayer-Staffel-10-Band-2-W-nsche-Buffy-the-Vampire-Slayer---Staffel-10-by-Christos-Gage.pdf
    • http://peldoaio.myhome.cx/13d03d23d13d03d43d6/Buffy-the-Vampire-Slayer-Staffel-8-Bd-5-Harmony-live-Buffy-the-Vampire-Slayer---Staffel-8-by-Joss-Whedon.pdf
    • http://peldoaio.myhome.cx/23d63d13d83d43d6/Cursed-Buffy-the-Vampire-Slayer-Season-6-1-Angel-Season-3-1-by-Mel-Odom.pdf
    • http://peldoaio.myhome.cx/73d83d03d83d6/Revenant-Buffy-the-Vampire-Slayer-Season-3-11-by-Mel-Odom.pdf
    • http://peldoaio.myhome.cx/33d03d43d63d13d6/Buffy-the-Vampire-Slayer-On-Your-Own-Part-1-Season-9-6-by-Andrew-Chambliss.pdf
    • http://peldoaio.myhome.cx/33d93d63d93d13d7/Prime-Evil-Buffy-the-Vampire-Slayer-Season-3-10-by-Diana-G-Gallagher.pdf
    • http://peldoaio.myhome.cx/33d43d23d23d63d1/Buffy-the-Vampire-Slayer-The-Script-Book-Season-Two-Vol-1-by-Gertrude-Pocket.pdf
    • http://peldoaio.myhome.cx/33d03d43d83d23d9/Buffy-the-Vampire-Slayer-Guarded-Season-9-Volume-3-by-Andrew-Chambliss.pdf
    • http://peldoaio.myhome.cx/73d83d93d03d03d9/Croqueuses-de-cadavres-Buffy-the-Vampire-Slayer-Season-3-4-by-John-Passarella.pdf
    • http://peldoaio.myhome.cx/43d43d13d23d6/The-Book-of-Fours-Buffy-the-Vampire-Slayer-Season-3-23-by-Nancy-Holder.pdf