Malicious PDF — malware analysis report

Static analysis result for SHA-256 76774c14783eeb3b…

MALICIOUS

PDF

29.1 KB Created: 2020-03-18 21:06:45 +00:00 Authoring application: mPDF 5.7
MD5: e5d0ccf52803e58718d2488465db0ace SHA-1: 3a45f9d42cad031c79976504e892ba09a0bf35c3 SHA-256: 76774c14783eeb3ba67849d15506b18428450b60f7667bc5146d498f8598a428
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which are presented as book titles. These links likely lead to malicious websites designed to exploit users. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of this document. No scripts were extracted, but the embedded links are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9700

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/1555554552553556/OSS-The-Secret-History-of-America-s-First-Central-Intelligence-Agency-by-Richard-Harris-Smith.pdf
    • http://ieuicufioao.myhome.cx/5550558554552559/Creating-the-Secret-State-The-Origins-of-the-Central-Intelligence-Agency-1943-1947-by-David-F-Rudgers.pdf
    • http://ieuicufioao.myhome.cx/8559555550553/The-Puzzle-Palace-Inside-the-National-Security-Agency-America-s-Most-Secret-Intelligence-Organization-by-James-Bamford.pdf
    • http://ieuicufioao.myhome.cx/3553556552552554/The-Torture-Report-Committee-Study-of-the-Central-Intelligence-Agency-s-Detention-and-Interrogation-Program-Executive-Summary-Findings-and-Conclusions-by-Senate-Select-Committee-on-Intelligence.pdf
    • http://ieuicufioao.myhome.cx/6550553556559558/DJIBOUTI-Country-Studies-A-brief-comprehensive-study-of-Djibouti-by-Central-Intelligence-Agency.pdf
    • http://ieuicufioao.myhome.cx/1550553556552559550/South-America-and-Central-America-A-Natural-History-by-Jean-Dorst.pdf
    • http://ieuicufioao.myhome.cx/5552551559552556/Ancient-Mexico-amp-Central-America-Archaeology-and-Culture-History-by-Susan-Toby-Evans.pdf
    • http://ieuicufioao.myhome.cx/1554550552550552/A-Natural-History-of-Trees-of-Eastern-and-Central-North-America-by-Donald-Culross-Peattie.pdf
    • http://ieuicufioao.myhome.cx/5551559559551557/Combined-Fleet-Decoded-The-Secret-History-of-American-Intelligence-and-the-Japanese-Navy-in-World-War-II-by-John-Prados.pdf
    • http://ieuicufioao.myhome.cx/5550555557553555/The-Smithsonian-s-History-of-America-in-101-Objects-by-Richard-Kurin.pdf
    • http://ieuicufioao.myhome.cx/1555553552557/The-Shaping-of-America-A-People-s-History-of-the-Young-Republic-by-Page-Smith.pdf
    • http://ieuicufioao.myhome.cx/3556558552550552/Colonial-America-A-History-1565---1776-by-C-Richard-Middleton.pdf
    • http://ieuicufioao.myhome.cx/3554559553550554/The-King-of-Men-Middle-Earth-The-Secret-History-3-by-Richard-Warren.pdf
    • http://ieuicufioao.myhome.cx/5556552559/The-Color-of-Law-A-Forgotten-History-of-How-Our-Government-Segregated-America-by-Richard-Rothstein.pdf
    • http://ieuicufioao.myhome.cx/3554559556557556/The-City-of-the-King-of-the-Elves-Middle-Earth-The-Secret-History-11-by-Richard-Warren.pdf
    • http://ieuicufioao.myhome.cx/1554551557553556/Dry-Store-Room-No-1-The-Secret-Life-of-the-Natural-History-Museum-by-Richard-Fortey.pdf
    • http://ieuicufioao.myhome.cx/2557557558556554/Better-for-All-the-World-The-Secret-History-of-Forced-Sterilization-and-America-s-Quest-for-Racial-Purity-by-Harry-Bruinius.pdf
    • http://ieuicufioao.myhome.cx/8555550550553/Area-51---Black-Jets-A-History-of-the-Aircraft-Developed-at-Groom-Lake-America-s-Secret-Aviation-Base-by-Bill-Yenne.pdf
    • http://ieuicufioao.myhome.cx/5551555559555557/British-Military-Intelligence-In-The-Crimean-War-1854-1856-by-Stephen-M-Harris.pdf
    • http://ieuicufioao.myhome.cx/2559555558558554/The-No-1-Ladies-Detective-Agency-No-1-Ladies-Detective-Agency-1-by-Alexander-McCall-Smith.pdf