Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a9babe4b736baa6…

MALICIOUS

PDF

22.9 KB Created: 2020-03-20 01:05:42 +00:00 Authoring application: mPDF 5.7
MD5: a32cbbaee03c8d8ada8965b010a747cf SHA-1: ec40dc44a4325cf894ef814436d6f59fee0b3d07 SHA-256: 7a9babe4b736baa65015c3f891e2b11f4800159245e8128d71ee79fceb782cab
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links, such as http://ieuicufioao.myhome.cx/3558556551559556/Preventing-Bipolar-Relapse-A-Lifestyle-Program-to-Help-You-Maintain-a-Balanced-Mood-and-Live-Well-by-Ruth-C-White.pdf, likely lead to malicious content or further stages of an attack. The ML classifier also strongly flagged this PDF as malicious. The presence of embedded links suggests an attempt to direct the user to external resources, which is a common tactic for malware delivery or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9726

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/3558556551559556/Preventing-Bipolar-Relapse-A-Lifestyle-Program-to-Help-You-Maintain-a-Balanced-Mood-and-Live-Well-by-Ruth-C-White.pdf
    • http://ieuicufioao.myhome.cx/5557552554550553/Mindfulness-Based-Cognitive-Therapy-for-Depression-A-New-Approach-to-Preventing-Relapse-by-Zindel-V-Segal.pdf
    • http://ieuicufioao.myhome.cx/1551553557551559555/Internet-affiliate-with-ClickBank-Live-your-lifestyle-by-Ayoub.pdf
    • http://ieuicufioao.myhome.cx/2555553554553551/Full-Color-Life-How-to-Live-a-Creative-Balanced-Life-by-Margery-Walshaw.pdf
    • http://ieuicufioao.myhome.cx/1554552552554557/Judy-Moody-was-in-a-Mood-Not-a-Good-Mood-A-Bad-Mood-Judy-Moody-1-by-Megan-McDonald.pdf
    • http://ieuicufioao.myhome.cx/9558556552551551/The-Program-Alan-Gregory-9-by-Stephen-White.pdf
    • http://ieuicufioao.myhome.cx/3552553559552554/Live-Flesh-by-Ruth-Rendell.pdf
    • http://ieuicufioao.myhome.cx/3558556556559552/Conquer-Your-Critical-Inner-Voice-A-Revolutionary-Program-to-Counter-Negative-Thoughts-and-Live-Free-from-Imagined-Limitations-by-Robert-W-Firestone.pdf
    • http://ieuicufioao.myhome.cx/4555552555552550/Destined-to-Live-A-True-Story-of-a-Child-in-the-Holocaust-by-Ruth-Gruener.pdf
    • http://ieuicufioao.myhome.cx/4550556556557558/White-Horizon-by-Jan-Ruth.pdf
    • http://ieuicufioao.myhome.cx/1551559556558552554/David-Kirsch-s-Ultimate-Family-Wellness-Plan-Live-Well-Together-with-the-No-Fail-No-Excuses-Fitness-and-Nutrition-Program-by-David-Kirsch.pdf
    • http://ieuicufioao.myhome.cx/1558556550552552/A-Month-of-Sundays-by-Ruth-White.pdf
    • http://ieuicufioao.myhome.cx/2553551559559554/Lonely-Learning-to-Live-with-Solitude-by-Emily-White.pdf
    • http://ieuicufioao.myhome.cx/9558552554559550/Charlotte-and-the-White-Horse-by-Ruth-Krauss.pdf
    • http://ieuicufioao.myhome.cx/1557554556556556/Black-amp-White-Roses-by-Ruth-Watson-Morris.pdf
    • http://ieuicufioao.myhome.cx/3552550557556558/Rose-Red-amp-Snow-White-A-Grimms-Fairy-Tale-by-Ruth-Sanderson.pdf
    • http://ieuicufioao.myhome.cx/1551554555555557554/Love-Live-Freedom-Traute-Lafrenz-and-the-White-Rose-by-Peter-Normann-Waage.pdf
    • http://ieuicufioao.myhome.cx/7550554558554555/Works-by-Ruth-Rendell-Study-Guide-Books-by-Ruth-Rendell-Novels-by-Ruth-Rendell-Short-Story-Collections-by-Ruth-Rendell-the-Water-s-Lovely-by-Books-LLC.pdf
    • http://ieuicufioao.myhome.cx/3552558558557553/The-Program-The-Program-1-by-Suzanne-Young.pdf
    • http://ieuicufioao.myhome.cx/6551551556558556/The-Trainee-Program-Guide-How-to-Survive-and-Prosper-as-Part-of-a-Trainee-Program-by-Patrick-Jonsson.pdf