Malicious PDF — malware analysis report

Static analysis result for SHA-256 646376f9244d4404…

MALICIOUS

PDF

17.3 KB Created: 2020-03-15 14:45:00 +00:00 Authoring application: mPDF 5.7
MD5: 8813bc0c7bf390e9c8130cffba8e0690 SHA-1: 761bdd076373b8a2c51b5b48cd4d3fc038deb875 SHA-256: 646376f9244d4404c9cc032c1cb4d5d68dad96f5157cadd39e3144b5a11eb47f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files on a single suspicious domain, identified by the PDF_SEO_LINK_FARM heuristic. This suggests a tactic to drive traffic or distribute further content, potentially malicious. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weasciaoak.myhome.cx/22d32d62d02d32d1/La-chair-disparue-Les-gestionnaires-de-l-Apocalypse-1-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/22d32d62d02d42d8/L-argent-du-monde-2-Les-gestionnaires-de-l-apocalypse-2-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/22d32d62d02d72d5/Le-Bien-des-Autres-2-Les-gestionnaires-de-l-apocalypse-3-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/22d32d62d02d42d2/L-argent-du-monde-1-Les-gestionnaires-de-l-apocalypse-2-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/22d32d62d02d72d1/Le-Bien-des-Autres-1-Les-gestionnaires-de-l-apocalypse-3-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/52d92d92d22d32d3/Le-bien-des-autres-Les-gestionnaires-de-l-apocalypse-3-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/52d72d52d72d42d2/La-faim-de-la-terre-Les-Gestionnaires-de-l-apocalypse-4-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/22d32d62d02d62d5/La-faim-de-la-terre---partie-2-Les-gestionnaires-de-l-Apocalypse-4-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/22d32d62d02d52d7/La-faim-de-la-terre---partie-1-Les-gestionnaires-de-l-Apocalypse-4-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/52d72d02d12d12d1/Int-rieurs-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/62d32d02d72d02d7/Les-visages-de-l-humanit-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/52d62d42d32d22d4/La-fabrique-de-l-ext-me-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/62d62d92d92d12d6/Deux-balles-un-sourire-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/52d22d62d52d62d5/La-femme-trop-tard-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/62d32d02d62d72d1/L-homme-trafiqu-Les-d-buts-de-F-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/62d32d02d72d72d9/Dix-petits-hommes-blancs-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/62d32d02d62d72d3/Blunt-les-treize-derniers-jours-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/82d02d12d02d52d3/Notre-chair-disparue-by-Gilles-Maurice-Dumoulin.pdf
    • http://weasciaoak.myhome.cx/62d72d82d82d82d9/-crire-pour-inqui-ter-et-pour-construire-by-Jean-Jacques-Pelletier.pdf
    • http://weasciaoak.myhome.cx/62d32d52d72d32d0/La-disparue-de-linton-hill-by-Jean-Michel-Payet.pdf