Malicious PDF — malware analysis report

Static analysis result for SHA-256 83052e3b098ddaaa…

MALICIOUS

PDF

30.8 KB Created: 2020-03-19 20:57:58 +00:00 Authoring application: mPDF 5.7
MD5: d6602f59a5937979361de621060d20a0 SHA-1: d19806d08b6ae34f9ef2a5562a77602ac2679a33 SHA-256: 83052e3b098ddaaacd81679f6a8925c3a78b116755795201a848973a8273d55d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a single domain, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. The embedded URLs likely serve as a lure to direct users to potentially malicious content or further phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9720

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kitasdyu.myhome.cx/1870875878875879877/Dinah-and-Virginia-by-Priscilla-C-Hallowell.pdf
    • http://kitasdyu.myhome.cx/2875878874870875/Priscilla-the-Great-The-Kiss-of-Life-Priscilla-the-Great-2-by-Sybil-Nelson.pdf
    • http://kitasdyu.myhome.cx/6870875873875871/Priscilla-Hauser-s-Book-of-Tole-and-Decorative-Painting-by-Priscilla-Hauser.pdf
    • http://kitasdyu.myhome.cx/4879875874875870/Dinah-s-Dark-Desire-Dinah-s-Desire-1-by-Mechele-Armstrong.pdf
    • http://kitasdyu.myhome.cx/1870875878874877874/Dinah-Jefferies-3-Book-Collection-by-Dinah-Jefferies.pdf
    • http://kitasdyu.myhome.cx/5871872877877873/The-August-Gales-by-Gerald-Hallowell.pdf
    • http://kitasdyu.myhome.cx/1871872871871876876/Shadowed---Unheard-Voices-by-Joell-Hallowell.pdf
    • http://kitasdyu.myhome.cx/9875877871876870/The-Official-Letters-Of-Alexander-Spotswood-Lieutenant-governor-Of-The-Colony-Of-Virginia-1710-1722-Now-First-Printed-From-The-Manuscript-In-The-Collections-Of-The-Virginia-Historical-Society-by-Virginia-Lieutenant-Governor.pdf
    • http://kitasdyu.myhome.cx/9875877871876876/The-Official-Letters-of-Alexander-Spotswood-Lieutenant-Governor-of-the-Colony-of-Virginia-1710-1722-Now-First-Printed-from-the-Manuscript-in-the-Collections-of-the-Virginia-Historical-Society-Volume-2-by-Virginia-Lieutenant-Governor.pdf
    • http://kitasdyu.myhome.cx/9875877871876874/The-Official-Letters-of-Alexander-Spotswood-Lieutenant-Governor-of-the-Colony-of-Virginia-1710-1722-Now-First-Printed-from-the-Manuscript-in-the-Collections-of-the-Virginia-Historical-Society-by-Robert-Alonzo-Brock.pdf
    • http://kitasdyu.myhome.cx/8875872873878871/Journals-of-the-House-of-Burgesses-of-Virginia-1659-60-1693-by-Virginia-General-Assembly-House-of-Bur.pdf
    • http://kitasdyu.myhome.cx/1870875878874877878/Dinah-s-Egg-by-Lee-Lorenz.pdf
    • http://kitasdyu.myhome.cx/4870878879872878/The-Diary-of-Virginia-Woolf-Volume-One-1915-1919-by-Virginia-Woolf.pdf
    • http://kitasdyu.myhome.cx/1870875878873877872/Dinah-by-Bruce-Cassiday.pdf
    • http://kitasdyu.myhome.cx/1870875878872878875/Before-the-Rains-by-Dinah-Jefferies.pdf
    • http://kitasdyu.myhome.cx/1870875878873877879/Touchstone-by-Dinah-McCall.pdf
    • http://kitasdyu.myhome.cx/5873871879877878/TO-THE-LIGHTHOUSE-by-Virginia-Woolf-author-of-The-Voyage-Out-Night-and-Day-Jacob-s-Room-Mrs-Dalloway-To-the-Lighthouse-Orlando-The-Waves-The-Years-and-Between-the-Acts-Annotated-by-Virginia-Woolf.pdf
    • http://kitasdyu.myhome.cx/5873872870871872/ORLANDO-by-Virginia-Woolf-author-of-The-Voyage-Out-Night-and-Day-Jacob-s-Room-Mrs-Dalloway-To-the-Lighthouse-Orlando-The-Waves-The-Years-and-Between-the-Acts-Annotated-by-Virginia-Woolf.pdf
    • http://kitasdyu.myhome.cx/9875877870873874/The-Official-Letters-of-Alexander-Spotswood-Lieutenant-Governor-of-the-Colony-of-Virginia-1710-1722-Vol-1-Now-First-Printed-from-the-Manuscript-in-the-Collections-of-the-Virginia-Historical-Society-by-Alexander-Spotswood.pdf
    • http://kitasdyu.myhome.cx/4870873873877/Back-to-You-by-Priscilla-Glenn.pdf