Malicious PDF — malware analysis report

Static analysis result for SHA-256 876dcb08e2bbce15…

MALICIOUS

PDF

20.1 KB Created: 2020-03-20 17:32:07 +00:00 Authoring application: mPDF 5.7
MD5: ebd0862d6d9aec075e4419cc7df4bc07 SHA-1: a40608b1f58e86bdcced53f9323268097c9e5ca8 SHA-256: 876dcb08e2bbce152dcf1434538c99a84283f14225fdbb702699e820138040c1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, primarily `weisncio.myhome.cx`, and appear to be designed to direct users to external content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. The embedded links likely serve as a lure to download further malicious payloads or redirect to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1624623623620626/Machiavellian-Poker-Strategy-How-to-Play-Like-a-Prince-and-Rule-the-Poker-Table-by-David-Apostolico.pdf
    • http://weisncio.myhome.cx/3627629627627624/Play-Poker-Like-the-Pros-The-greatest-poker-player-in-the-world-today-reveals-his-million-dollar-winning-strategies-to-the-most-popular-tournament-home-and-online-games-by-Phil-Hellmuth.pdf
    • http://weisncio.myhome.cx/1620626628623627625/The-Raiser-s-Edge-Tournament-Poker-Strategies-for-Today-s-Aggressive-Game-by-Bertrand-Grospellier.pdf
    • http://weisncio.myhome.cx/4621624628629624/The-Theory-of-Poker-by-David-Sklansky.pdf
    • http://weisncio.myhome.cx/1620626624622628623/Draw-Poker-Odds-The-Mathematics-of-Classical-Poker-by-Catalin-Barboianu.pdf
    • http://weisncio.myhome.cx/4621624628628627/Hold-Em-Poker-for-Advanced-Players-by-David-Sklansky.pdf
    • http://weisncio.myhome.cx/1621627625625628623/The-Hand-I-Played-A-Poker-Memoir-by-David-Spanier.pdf
    • http://weisncio.myhome.cx/1627627624622628/Poker-Face-Poker-Face-1-by-Adriana-Law.pdf
    • http://weisncio.myhome.cx/1621628629624626/Tournament-by-Jennifer-Goebel.pdf
    • http://weisncio.myhome.cx/9624621628623625/Poker-strategisch-und-ertragreich-gewinnen-Poker-strategisch-und-ertragreich-gewinnen-by-D-Selzer-McKenzie.pdf
    • http://weisncio.myhome.cx/2627621627625629/Tournament-of-Losers-by-Megan-Derr.pdf
    • http://weisncio.myhome.cx/1620623625623629621/Blue-Mage-Equinox-Tournament-of-Mages-2-by-Cleave-Bourbon.pdf
    • http://weisncio.myhome.cx/4629626627623625/The-Tournament-at-Gorlan-Ranger-s-Apprentice-The-Early-Years-1-by-John-Flanagan.pdf
    • http://weisncio.myhome.cx/8629625620625621/March-1939-Before-the-Madness--The-Story-of-the-First-NCAA-Basketball-Tournament-Champions-by-Terry-Frei.pdf
    • http://weisncio.myhome.cx/1620625627621627623/How-March-Became-Madness-How-the-NCAA-Tournament-Became-the-Greatest-Sporting-Event-in-America-by-Eddie-Einhorn.pdf
    • http://weisncio.myhome.cx/9621622620620626/Elements-of-Poker-by-Tommy-Angelo.pdf
    • http://weisncio.myhome.cx/7622627624623628/The-Mathematics-of-Poker-by-Bill-Chen.pdf
    • http://weisncio.myhome.cx/1623626629626620/Liar-s-Poker-by-Michael-Lewis.pdf
    • http://weisncio.myhome.cx/3621627622620626/The-Strip-Poker-Club-by-Cheri-Grade.pdf
    • http://weisncio.myhome.cx/1624627620626626/Dead-Man-s-Bluff-Poker-Face-2-by-Adriana-Law.pdf