Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c43937f4f29cd1c…

MALICIOUS

PDF

17.3 KB Created: 2020-03-18 21:50:24 +00:00 Authoring application: mPDF 5.7
MD5: f113504372f72c33801f2168b4c03571 SHA-1: 70691d03ee6a28f1b54809e9eaf8ddafddb35c01 SHA-256: 8c43937f4f29cd1cfd09b4ab0292e4fbe632d18917fae135e0d04c8c3ffda7c9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents on the domain weasciaoak.myhome.cx. This is indicative of a link farm, likely intended to drive traffic or distribute further malicious content. The ML classifier also flagged this PDF as malicious with a high score. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weasciaoak.myhome.cx/72d12d52d02d92d1/Cinq-nouvelles-fantastiques-du-XXIe-si-cle-by-Pierre-Cendors.pdf
    • http://weasciaoak.myhome.cx/52d52d42d42d62d8/L-invisible-dehors-by-Pierre-Cendors.pdf
    • http://weasciaoak.myhome.cx/92d52d82d92d42d9/Millennium-Est-cinq-histoires-fantastiques-by-Jeff-VanderMeer.pdf
    • http://weasciaoak.myhome.cx/92d92d82d52d8/Le-Horla-et-autres-nouvelles-fantastiques-by-Guy-de-Maupassant.pdf
    • http://weasciaoak.myhome.cx/72d62d12d12d12d3/Le-Horla-et-autres-nouvelles-fantastiques-by-Guy-de-Maupassant.pdf
    • http://weasciaoak.myhome.cx/52d32d82d82d12d7/Le-Portrait-De-Dorian-Gray-Nouvelles-Fantastiques-by-Oscar-Wilde.pdf
    • http://weasciaoak.myhome.cx/62d62d12d02d22d9/Le-Horla-Et-Autres-Nouvelles-Fantastiques-1875-1890-by-Guy-de-Maupassant.pdf
    • http://weasciaoak.myhome.cx/82d02d82d52d92d9/France-Grande-Bretagne-dans-l-oc-an-Indien-XVIIe-XXIe-si-cles-De-la-rivalit-l-alliance-suivi-de-L-esclavage-Bourbon-Nouvelles-approches-2010-by-AHIOI.pdf
    • http://weasciaoak.myhome.cx/52d32d82d92d52d2/Nocturnes-cinq-nouvelles-de-musique-au-cr-puscule-by-Kazuo-Ishiguro.pdf
    • http://weasciaoak.myhome.cx/62d12d62d72d12d3/Cinq-nouvelles-histoires-de-Ranolet-et-Bufolet-by-Arnold-Lobel.pdf
    • http://weasciaoak.myhome.cx/52d72d52d42d12d0/Sprint-Comment-r-soudre-les-probl-mes-et-trouver-de-nouvelles-id-es-en-cinq-jours-by-Jake-Knapp.pdf
    • http://weasciaoak.myhome.cx/62d22d82d32d22d8/Le-Jourde-amp-Naulleau-Pr-cis-de-litt-rature-du-XXIe-si-cle-by-Pierre-Jourde.pdf
    • http://weasciaoak.myhome.cx/62d12d62d72d22d2/Le-Cid-Tragedie-En-Cinq-Actes-by-Pierre-Corneille.pdf
    • http://weasciaoak.myhome.cx/52d82d32d12d02d5/Derni-res-Nouvelles-de-la-Terre-by-Pierre-Bordage.pdf
    • http://weasciaoak.myhome.cx/62d02d42d22d02d1/Cinq-heures-vingt-cinq-by-Agatha-Christie.pdf
    • http://weasciaoak.myhome.cx/82d42d02d02d42d2/Hecatombe-Nouvelles-Bucoliques-by-Jean-Pierre-Rochat.pdf
    • http://weasciaoak.myhome.cx/62d72d52d42d52d8/Romans-r-cits-nouvelles-by-Pierre-Drieu-la-Rochelle.pdf
    • http://weasciaoak.myhome.cx/62d42d42d52d62d7/Bonnes-nouvelles-des-toiles-by-Jean-Pierre-Luminet.pdf
    • http://weasciaoak.myhome.cx/82d32d82d32d22d5/Les-nouvelles-politiques-urbaines-by-Jean-Pierre-Gaudin.pdf
    • http://weasciaoak.myhome.cx/72d02d32d82d62d5/Fausses-nouvelles-du-21e-arrondissement-by-Jean-Pierre-Huster.pdf
    • http://weasciaoak.myhom