Malicious PDF — malware analysis report

Static analysis result for SHA-256 8bb7f7f5811ca6c4…

MALICIOUS

PDF

16.1 KB Created: 2020-03-18 18:42:35 +00:00 Authoring application: mPDF 5.7
MD5: f48448fae9288517c37a7cafe8692a14 SHA-1: 345cf0ce9dc43627455f95ab83052634889bea4d SHA-256: 8bb7f7f5811ca6c4991f80f33462894183ba47dc1fb699ce7f25efc73c63fbf7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a link farm with over 20 external URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with a high score. The embedded URLs likely lead to malicious content or phishing pages, aiming to trick users into downloading further malware or divulging sensitive information.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/8622621624628/The-Tiger-s-Fang-Graphic-Novel-by-Paul-Twitchell.pdf
    • http://weisncio.myhome.cx/8623620628620626/Witchblade-Talons-by-John-DeChancie.pdf
    • http://weisncio.myhome.cx/6625621628627629/Pistolet-et-talons-hauts-by-Sylvie-G-.pdf
    • http://weisncio.myhome.cx/4626624628/Talons-of-Power-Wings-of-Fire-9-by-Tui-T-Sutherland.pdf
    • http://weisncio.myhome.cx/3628620628628629/Talons-Caged-Desire-by-Sydney-Somers.pdf
    • http://weisncio.myhome.cx/7625627627627625/Now-Is-The-Time-by-Paul-Grondahl.pdf
    • http://weisncio.myhome.cx/8623620627625628/The-Talons-of-the-Eagle-Crystal-Birds-2-by-Lene-Kaaberb-l.pdf
    • http://weisncio.myhome.cx/7628624626628622/Time-Will-Tell-Conversations-With-Paul-Bley-by-Paul-Bley.pdf
    • http://weisncio.myhome.cx/4625626626629623/Mended-Steel-Talons-Motorcycle-Club-2-by-Evelyn-Glass.pdf
    • http://weisncio.myhome.cx/4625626626628629/Broken-Steel-Talons-Motorcycle-Club-1-by-Evelyn-Glass.pdf
    • http://weisncio.myhome.cx/4625626626629626/Indivisible-Steel-Talons-Motorcycle-Club-3-by-Evelyn-Glass.pdf
    • http://weisncio.myhome.cx/6627623624621621/Time-and-Narrative-Volume-2-by-Paul-Ric-ur.pdf
    • http://weisncio.myhome.cx/6621620626626626/Borrowed-Time-Love-Alone-Becoming-a-Man-by-Paul-Monette.pdf
    • http://weisncio.myhome.cx/2621620624625626/For-Time-And-All-Eternity-by-Paul-Dayton-Bailey.pdf
    • http://weisncio.myhome.cx/1621628626625629/Time-Was---A-romantic-comedy-with-a-kink-by-Paul-Adams.pdf
    • http://weisncio.myhome.cx/1621624621624626621/About-Time-Einstein-s-Unfinished-Revolution-by-Paul-Davies.pdf
    • http://weisncio.myhome.cx/2627620628624623/Paul-s-Missionary-Methods-In-His-Time-and-Ours-by-Robert-L-Plummer.pdf
    • http://weisncio.myhome.cx/6626627620622623/An-Oasis-in-Time-How-a-Day-of-Rest-Can-Save-Your-Life-by-Marilyn-Paul.pdf
    • http://weisncio.myhome.cx/7627623620628623/In-Pursuit-of-the-Common-Good-Twenty-Five-Years-of-Improving-the-World-One-Bottle-of-Salad-Dressing-at-a-Time-by-Paul-Newman.pdf
    • http://weisncio.myhome.cx/4621620620629626/A-Time-Travel-Fantasy-Bundle-Footsteps-in-Time-Prince-of-Time-After-Cilmeri-1-2-by-Sarah-Woodbury.pdf