Malicious PDF — malware analysis report

Static analysis result for SHA-256 8174fd00670acff6…

MALICIOUS

PDF

21.3 KB Created: 2020-03-18 16:32:39 +00:00 Authoring application: mPDF 5.7
MD5: 2a2e707b3fb83f5395e677ca658b023a SHA-1: 0589b38353ff25ace873e78a37620a3581916a70 SHA-256: 8174fd00670acff64e453142ae156634650fce465bfe272e1f16d145bec8ae48
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'laoieoa.myhome.cx'. This behavior is indicative of a link farm or a lure to a malicious site, likely intended to distribute further malware or phish for credentials. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/2c08c03c07c02c05/Gerard-amp-Jacques-Volume-1-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/2c08c04c01c00c00/Fumi-Yoshinaga-s-Lovers-in-the-Night-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/1c00c05c09c00c07c04/What-Did-You-Eat-Yesterday-Volume-6-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/1c00c05c09c00c08c00/What-Did-You-Eat-Yesterday-Volume-8-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/1c00c05c08c09c09c08/Antique-Bakery-Volume-4-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/1c00c05c08c09c09c05/Antique-Bakery-Volume-2-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/2c08c03c08c08c03/Flower-of-Life-Volume-1-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/1c00c05c09c00c08c01/Ichigenme-the-First-Class-Is-Civil-Law-Volume-2-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/2c06c01c09c07c03/All-My-Darling-Daughters-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/4c04c00c05c03c06/-oku-The-Inner-Chambers-Volume-5-oku-The-Inner-Chambers-5-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/4c08c05c05c03c09/-oku-The-Inner-Chambers-Volume-6-oku-The-Inner-Chambers-6-by-Fumi-Yoshinaga.pdf
    • http://laoieoa.myhome.cx/1c00c08c00c00c07c07/Betenden-Christen-Erste-Bis-Achte-Einsamkeit-Volume-4-by-Jacques-Nouet.pdf
    • http://laoieoa.myhome.cx/6c09c02c03c09c01/Recreations-in-Mathematics-and-Natural-Philosophy-In-Four-Volumes-Volume-I-by-Jacques-Ozanam.pdf
    • http://laoieoa.myhome.cx/8c02c02c08c00c03/Mir-Catalogue-Raisonnn-Drawings-Volume-II-1938-1959-by-Jacques-Dupin.pdf
    • http://laoieoa.myhome.cx/5c00c01c03c08/The-Adventures-of-Jewel-Cardwell-by-Fumi-Hancock.pdf
    • http://laoieoa.myhome.cx/5c08c04c01c07c02/New-Travels-in-the-United-States-of-America-Performed-in-MDCCLXXXVIII-Containing-the-Latest-and-Most-Accurate-Observations-on-the-Character-Genius-and-Present-State-of-the-People-and-Government-of-That-Country-Their-Volume-2-of-2-by-Jacques-Pierre-Brissot-De-Warville.pdf
    • http://laoieoa.myhome.cx/2c05c06c05c09c06/The-Seminar-of-Jacques-Lacan-Book-II-The-Ego-in-Freud-s-Theory-and-in-the-Technique-of-Psychoanalysis-1954-1955-by-Jacques-Lacan.pdf
    • http://laoieoa.myhome.cx/6c05c07c07c03c03/Jacques-Lanzmann-Presente-La-Defense-Un-Musee-En-Plein-Ciel-by-Jacques-Lanzmann.pdf
    • http://laoieoa.myhome.cx/7c07c03c04c07c03/Jacques-G-n-reux-explique-l-conomie-tout-le-monde-by-Jacques-G-n-reux.pdf
    • http://laoieoa.myhome.cx/8c03c01c09c05c04/Feminine-Sexuality-Jacques-Lacan-and-the-cole-freudienne-by-Jacques-Lacan.pdf