Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ab89cbfa5d6d474…

MALICIOUS

PDF

22.5 KB Created: 2020-03-20 13:12:16 +00:00 Authoring application: mPDF 5.7
MD5: fc90cbf46902787d9778fe480d7bc902 SHA-1: dc022ab8c4bcea51e374865bff8710997a6a5b64 SHA-256: 7ab89cbfa5d6d4747ac78f15542f67565417eb037d87d4f2118868c5994fd2a9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to external resources, suggesting a tactic to manipulate search engine results or to redirect users to potentially malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/16a06a66a36a16a16a1/Crossing-the-Jabbok-Illness-and-Death-in-Askenazi-Judaism-in-Sixteenth---through-Nineteenth-Century-Prague-by-Sylvie-Anne-Goldberg.pdf
    • http://rtuninnsi.myhome.cx/26a06a16a16a96a7/Console-and-Classify-The-French-Psychiatric-Profession-in-the-Nineteenth-Century-by-Jan-E-Goldstein.pdf
    • http://rtuninnsi.myhome.cx/16a16a06a06a66a76a9/The-Illustrated-Bartsch-French-Artists-of-the-Nineteenth-Century-by-Petra-ten-Doesschate-Chu.pdf
    • http://rtuninnsi.myhome.cx/76a86a66a86a56a4/Coiffures-Hair-in-Nineteenth-Century-French-Literature-and-Culture-by-Carol-Rifelj.pdf
    • http://rtuninnsi.myhome.cx/76a66a26a16a86a3/The-Jews-in-Nineteenth-Century-France-From-the-French-Revolution-to-the-Alliance-Isra-lite-Universelle-by-Michael-Graetz.pdf
    • http://rtuninnsi.myhome.cx/76a26a16a36a36a9/Millennial-Visions-Feminism-in-to-the-21-Century-by-Carolyn-Brina.pdf
    • http://rtuninnsi.myhome.cx/96a26a96a76a16a0/The-Red-and-the-Black-A-Chronicle-of-the-Nineteenth-Century-by-Stendhal.pdf
    • http://rtuninnsi.myhome.cx/76a96a26a06a86a9/Capital-in-the-Nineteenth-Century-by-Paul-W-Rhode.pdf
    • http://rtuninnsi.myhome.cx/46a46a56a16a26a7/Paris-and-the-Nineteenth-Century-by-Christopher-Prendergast.pdf
    • http://rtuninnsi.myhome.cx/16a06a76a86a56a56a2/A-Photographic-Guide-to-Toy-Dolls-in-the-Nineteenth-Century-by-Max-Von-Boehn.pdf
    • http://rtuninnsi.myhome.cx/66a96a06a86a06a5/Feminism-Theory-in-French-Revolution-Painting-Le-Dernier-Appel-des-Condamn-s-by-Meg-Smolinski.pdf
    • http://rtuninnsi.myhome.cx/96a16a46a86a46a9/Unbeknownst-II-Time-Travel-Mid-Nineteenth-Century-Oregon-by-RC-Marlen.pdf
    • http://rtuninnsi.myhome.cx/26a36a46a26a0/Karl-Marx-A-Nineteenth-Century-Life-by-Jonathan-Sperber.pdf
    • http://rtuninnsi.myhome.cx/16a66a86a36a26a7/Horace-Greeley-Nineteenth-Century-Crusader-by-Glyndon-G-Van-Deusen.pdf
    • http://rtuninnsi.myhome.cx/16a56a36a06a5/The-Beechers-An-American-Family-in-the-Nineteenth-Century-by-Milton-Rugoff.pdf
    • http://rtuninnsi.myhome.cx/76a46a06a36a16a8/Cholera-Curse-of-the-Nineteenth-Century-by-Stephanie-True-Peters.pdf
    • http://rtuninnsi.myhome.cx/56a06a86a26a06a2/Secularism-and-Religion-in-Nineteenth-Century-Germany-by-Todd-H-Weir.pdf
    • http://rtuninnsi.myhome.cx/36a26a76a96a06a7/Anthology-of-Japanese-Literature-From-the-Earliest-Era-to-the-Mid-Nineteenth-Century-by-Donald-Keene.pdf
    • http://rtuninnsi.myhome.cx/26a76a96a26a76a6/A-Pickpocket-s-Tale-The-Underworld-of-Nineteenth-Century-New-York-by-Timothy-J-Gilfoyle.pdf
    • http://rtuninnsi.myhome.cx/16a76a96a36a16a9/Antebellum-at-Sea-Maritime-Fantasies-in-Nineteenth-Century-America-by-Jason-Berger.pdf