Malicious PDF — malware analysis report

Static analysis result for SHA-256 7baafa700eaeb145…

MALICIOUS

PDF

17.9 KB Created: 2020-03-18 21:57:42 +00:00 Authoring application: mPDF 5.7
MD5: 97c4e3e9a787090a192e248e08117f54 SHA-1: 26bf9fb0f5c25b865f07d3c2fdfef67c07694ac3 SHA-256: 7baafa700eaeb145e9bee4a89bdd0a7e8629e4665fb0832798faaec482aaa933
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'weisncio.myhome.cx'. This heuristic firing, combined with the ML classifier's high confidence, suggests a link farm or redirection scheme designed to lead users to potentially malicious content. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate intent beyond the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1620625622621626620/Choices-Running-With-Alphas-3-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624622625627622/Faith-Running-With-Alphas-5-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624624620621624/Home-Running-With-Alphas-7-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620625622621621624/Claimed-by-the-Alphas-Part-Three-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1625622621624628/Claimed-by-the-Alphas-Shifters-of-Appalachia-Book-1-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624622625627623/Taming-the-Alpha-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620625622621620628/Bound-to-the-Alpha-Part-One-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4629623623629623/The-Dragon-s-Appraiser-Part-Three-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620629624622628623/Grizzly-Bear-s-Bride-Greystone-Shifters-1-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1624625626622625/Chances-amp-Choices-Choices-1-by-Helen-Karol.pdf
    • http://weisncio.myhome.cx/1621620626620629/Choices-Choices-1-by-Annie-Brewer.pdf
    • http://weisncio.myhome.cx/1620624625625627627/Running-for-Mortals-A-Commonsense-Plan-for-Changing-Your-Life-With-Running-by-John-Bingham.pdf
    • http://weisncio.myhome.cx/4628629629628625/Lifelong-Running-Overcome-the-11-Myths-about-Running-and-Live-a-Healthier-Life-by-Ruth-E-Heidrich.pdf
    • http://weisncio.myhome.cx/1620624625625627623/Running-To-You-Running-Series-1-by-DeLaine-Roberts.pdf
    • http://weisncio.myhome.cx/2629627622621627/The-Kategan-Alphas-Vol-1-The-Kategan-Alphas-1--3-by-T-A-Grey.pdf
    • http://weisncio.myhome.cx/2625620628629627/Barefoot-Running-Step-by-Step-Barefoot-Ken-Bob-The-Guru-of-Shoeless-Running-Shares-His-Personal-Technique-by-Roy-Wallack.pdf
    • http://weisncio.myhome.cx/4625627627625628/Tempting-the-Dryad-Fada-Shapeshifter-3-by-Rebecca-Rivard.pdf
    • http://weisncio.myhome.cx/3621625622628622/Claiming-Valeria-Fada-Shapeshifter-2-by-Rebecca-Rivard.pdf
    • http://weisncio.myhome.cx/7629625628629629/Ceinture-fl-ch-e-La---Arrow-Sash-The---Aienkwire-atiatahna-by-Sylvain-Rivard.pdf
    • http://weisncio.myhome.cx/7624625623626629/Repertoire-Des-Baptemes-de-La-Paroisse-Gentilly-Comte-de-Nicolet-1784-1987-by-Marcelle-Rivard.pdf