Malicious PDF — malware analysis report

Static analysis result for SHA-256 64cad960e5b47583…

MALICIOUS

PDF

16.5 KB Created: 2020-03-20 12:03:42 +00:00 Authoring application: mPDF 5.7
MD5: f879eee9e83fee9c4dedab364b29bd49 SHA-1: 736f5d7f4731008e46bb41e93fc39ae4dab8f762 SHA-256: 64cad960e5b475837b32cb028e646acb40cdf7a972becd52b4ce222e523f7651
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm that likely serves to distribute pirated content or potentially malware. The ML classifier also flagged this PDF as malicious with high confidence. While no scripts were explicitly extracted, the structure and embedded URLs suggest an attempt to redirect users to malicious or unauthorized content, likely initiated via a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1557559550550554/Dominion-The-Coldfire-Trilogy-0-5-by-C-S-Friedman.pdf
    • http://ieuicufioao.myhome.cx/5550556557556/The-Coldfire-Trilogy-Black-Sun-Rising-When-True-Night-Falls-Crown-of-Shadows-by-C-S-Friedman.pdf
    • http://ieuicufioao.myhome.cx/5557557550550/The-Battle-for-Vast-Dominion-Trophy-Chase-Trilogy-3-by-George-Bryan-Polivka.pdf
    • http://ieuicufioao.myhome.cx/3556557553550557/Feast-of-Souls-The-Magister-Trilogy-1-by-C-S-Friedman.pdf
    • http://ieuicufioao.myhome.cx/1553553552550557/Feast-of-Souls-The-Magister-Trilogy-1-by-C-S-Friedman.pdf
    • http://ieuicufioao.myhome.cx/4551550557558/Feast-of-Souls-The-Magister-Trilogy-1-by-C-S-Friedman.pdf
    • http://ieuicufioao.myhome.cx/3550555556553557/Kinky-Friedman-s-Guide-to-Texas-Etiquette-Or-How-to-Get-to-Heaven-or-Hell-Without-Going-Through-Dallas-Fort-Worth-by-Kinky-Friedman.pdf
    • http://ieuicufioao.myhome.cx/4557557550551554/Dominion-of-Blades-Dominion-of-Blades-1-by-Matt-Dinniman.pdf
    • http://ieuicufioao.myhome.cx/4553555551556553/Curse-of-the-Missing-Puppet-Head-Kinky-Friedman-16-by-Kinky-Friedman.pdf
    • http://ieuicufioao.myhome.cx/4553552550550550/A-Case-of-Lone-Star-Kinky-Friedman-2-by-Kinky-Friedman.pdf
    • http://ieuicufioao.myhome.cx/4553551557558554/The-Prisoner-of-Vandam-Street-Kinky-Friedman-17-by-Kinky-Friedman.pdf
    • http://ieuicufioao.myhome.cx/6557552556559552/Night-s-Dominion-Vol-1-Night-s-Dominion-1-6-by-Ted-Naifeh.pdf
    • http://ieuicufioao.myhome.cx/2555551558557555/Dominion-by-C-J-Sansom.pdf
    • http://ieuicufioao.myhome.cx/1559552559558553/Dominion-of-the-Eth-Wings-2-by-J-C-Owens.pdf
    • http://ieuicufioao.myhome.cx/3553557551559558/Dominion-by-Masamune-Shirow.pdf
    • http://ieuicufioao.myhome.cx/1559556557556555/Becoming-His-Slave-Dominion-of-Brothers-1-by-Talon-P-S-.pdf
    • http://ieuicufioao.myhome.cx/6558553554552/Dominion-Life-After-3-by-Julie-Hall.pdf
    • http://ieuicufioao.myhome.cx/3552551559557550/Inheritance-Dominion-1-by-Lissa-Kasey.pdf
    • http://ieuicufioao.myhome.cx/1550557559557550559/Dominion-Jane-by-Mela-Remington.pdf
    • http://ieuicufioao.myhome.cx/3551552551550559/Dominion-Zoe-Martinique-6-by-Phaedra-Weldon.pdf