Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a73e90fe12c42ba…

MALICIOUS

PDF

16.5 KB Created: 2020-03-18 21:22:20 +00:00 Authoring application: mPDF 5.7
MD5: e0847cb0a8f96f2616e42dcc4d0d83e1 SHA-1: 03e6db9d76859bd52dae37c3776b0373b9b4cf36 SHA-256: 8a73e90fe12c42ba914c77ffd79c5db0bb63e65bd29477ef89c5e89e2d91f58a
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external URLs, a technique often used for SEO manipulation or to distribute further malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The primary attack pattern involves directing users to a link farm hosted on the 'myhome.cx' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7689282-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7689282-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/9551557554550553/Der-Tag-an-dem-ich-fliegen-lernte-by-Stefanie-Kremser.pdf
    • http://ieuicufioao.myhome.cx/1551555557550553555/Als-das-Nashorn-fliegen-lernte-by-Nadia-Adina-Rose.pdf
    • http://ieuicufioao.myhome.cx/9551557554550557/Bird-und-ich-und-der-Sommer-in-dem-ich-fliegen-lernte-by-Crystal-Chan.pdf
    • http://ieuicufioao.myhome.cx/1551553557551553551/Wie-ich-lernte-dir-zu-verzeihen-Wie-ich-lernte-2-by-Vanessa-Clark.pdf
    • http://ieuicufioao.myhome.cx/7557557550558553/Morituri-Wie-die-Fliegen-by-Klaus-Bock.pdf
    • http://ieuicufioao.myhome.cx/1550552553558556556/Flugangst-Ade---Mit-Herz-fliegen-by-Max-Schultheis.pdf
    • http://ieuicufioao.myhome.cx/9551557554550550/Die-Olchis-fliegen-in-die-Schule-by-Erhard-Dietl.pdf
    • http://ieuicufioao.myhome.cx/1551558553550550557/Juhu-Uhu-lernt-fliegen-by-Sascha-Wagner.pdf
    • http://ieuicufioao.myhome.cx/9551557554558552/Engel-fliegen-einsam-by-Patrick-Vogt.pdf
    • http://ieuicufioao.myhome.cx/9551557554559554/Weil-du-mich-das-Fliegen-lehrst-Roman-by-Lina-Wilms.pdf
    • http://ieuicufioao.myhome.cx/1550552553558559556/Strategien-f-r-entspanntes-Fliegen-Ein-Selbsthilfeprogramm-zur-Bew-ltigung-von-Flugangst-by-Andreas-M-hlberger.pdf
    • http://ieuicufioao.myhome.cx/9551557556556556/Warum-Pechv-gel-fliegen-k-nnen-Die-Schutzengel-Trilogie-1-by-Jasmin-Whiscy.pdf
    • http://ieuicufioao.myhome.cx/8558554557554557/Das-Jahr-in-dem-ich-l-gen-lernte-by-Lauren-Wolk.pdf
    • http://ieuicufioao.myhome.cx/1551555557550557550/Wie-ich-lernte-das-Nutzlose-zu-lieben-by-Jupp-Hartmann.pdf
    • http://ieuicufioao.myhome.cx/1551555557550557553/Wie-meine-Frau-zu-gehorchen-lernte-by-Luca-Zanotti.pdf
    • http://ieuicufioao.myhome.cx/1551555557552557556/Mama-I-need-to-kotz-Was-ich-in-London-als-Mutter-lernte-by-Lucie-Marshall.pdf
    • http://ieuicufioao.myhome.cx/1551555557552557555/Wie-Pippa-wieder-lachen-lernte-Ein-Bilderbuch-f-r-Kinder-by-K-Pal-Handl.pdf
    • http://ieuicufioao.myhome.cx/7556554557558552/How-to-be-a-woman-Wie-ich-lernte-eine-Frau-zu-sein-by-Caitlin-Moran.pdf
    • http://ieuicufioao.myhome.cx/1550550559551554557/The-Romantics-oder-wie-Gael-das-mit-der-Liebe-lernte-by-Leah-Konen.pdf
    • http://ieuicufioao.myhome.cx/1551555557552552554/Depressionen-wie-ich-lernte-meine-Seele-auszutricksen-by-Maria-Berger.pdf