Malicious PDF — malware analysis report

Static analysis result for SHA-256 8f1efad792341887…

MALICIOUS

PDF

23.8 KB Created: 2020-03-19 03:35:31 +00:00 Authoring application: mPDF 5.7
MD5: 748b3484eddf8bb152ebc6f2f353a714 SHA-1: 6d9acc4480174778a18a2dc25da999fadcce7bbf SHA-256: 8f1efad792341887d16b9210ff06f5a32ae7d5cc2fc746d32a35c4abcf344316
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to external domains and appear to be part of a link farm strategy. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample. The primary attack pattern involves redirecting users to a multitude of external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9776

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/8c03c06c02c00/The-Art-of-Noir-The-Posters-and-Graphics-from-the-Classic-Era-of-Film-Noir-by-Eddie-Muller.pdf
    • http://laoieoa.myhome.cx/7c03c09c03c01c04/LE-MANTEAU-NOIR-putains-de-voisins-LE-MANTEAU-NOIR-t-1-by-MELpr-sente.pdf
    • http://laoieoa.myhome.cx/8c02c08c04c01c05/Boston-Noir-amp-Boston-Noir-2-The-Complete-Set-by-Dennis-Lehane.pdf
    • http://laoieoa.myhome.cx/1c00c06c09c05c02c02/Blanchis-by-Matthieu-SARRAZIN.pdf
    • http://laoieoa.myhome.cx/9c00c00c01c07c09/Elfe-Elfe-Noir-Elfe-Dans-La-Litterature-Fantasy-Et-Le-Jeu-de-Role-Haut-Elfe-Drow-Elfe-Sylvain-Loireag-Klabautermann-Alfe-Lumineux-Alfe-Sombre-Alfe-Noir-Co-Walker-Lady-Isabel-and-the-Elf-Knight-by-Source-Wikipedia.pdf
    • http://laoieoa.myhome.cx/9c06c09c08c05c06/Pl-doyer-f-r-die-Tiere-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/1c00c06c04c07c04c00/Oscar-Niemeyer-by-Matthieu-Salving.pdf
    • http://laoieoa.myhome.cx/7c00c07c06c05c01/Tibet-An-Inner-Journey-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/7c00c07c07c06c01/Monk-Dancers-of-Tibet-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/7c00c07c06c05c03/The-Language-of-Creation-Cosmic-Symbolism-in-Genesis-by-Matthieu-Pageau.pdf
    • http://laoieoa.myhome.cx/6c07c07c02c04c05/M-decin-du-RAID-Vivre-en-tat-d-urgence-by-Matthieu-Langlois.pdf
    • http://laoieoa.myhome.cx/7c00c07c06c01c07/Altruism-The-Power-of-Compassion-to-Change-Yourself-and-the-World-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/7c00c07c07c05c09/In-Search-of-Wisdom-A-Monk-a-Philosopher-and-a-Psychiatrist-on-What-Matters-Most-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/7c00c07c07c02c00/The-Forgotten-Monarch-Franz-Joseph-and-the-Outbreak-of-the-First-World-War-by-Matthieu-Santerre.pdf
    • http://laoieoa.myhome.cx/2c04c03c00c05c04/Happiness-A-Guide-to-Developing-Life-s-Most-Important-Skill-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/7c09c06c06c04c00/Matthieu-raconte-moi-ta-vie-au-paradis-Une-description-in-dite-de-l-apr-s-vie-by-Suzanne-Ward.pdf
    • http://laoieoa.myhome.cx/7c00c07c06c02c03/Cerveau-et-m-ditation-Dialogue-entre-le-bouddhisme-et-les-neurosciences-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/3c09c02c05c00c01/The-Quantum-and-the-Lotus-A-Journey-to-the-Frontiers-Where-Science-and-Buddhism-Meet-by-Matthieu-Ricard.pdf
    • http://laoieoa.myhome.cx/5c07c03c01c03c02/La-nuit-des-temps-de-Ren-Barjavel-Fiche-de-lecture-Analyse-compl-te-de-l-oeuvre-by-Matthieu-Durel.pdf
    • http://laoieoa.myhome.cx/1c01c05c09c08c04c08/Noir-Le-Charme-by-Alabina.pdf
    • http://laoieoa.myhome.cx/9c06c09c08c05c