Malicious PDF — malware analysis report

Static analysis result for SHA-256 923502754bff9f15…

MALICIOUS

PDF

21.3 KB Created: 2020-03-20 12:04:24 +00:00 Authoring application: mPDF 5.7
MD5: 0c23530a85211a99a3ff3cbac3bde595 SHA-1: 5d057b0353272921a7976316960a1cddd7684730 SHA-256: 923502754bff9f15c416d83da40c24c31b54e7fb0a1829865c31fcc81bcfc1e3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents on the domain 'ieuicufioao.myhome.cx'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/2555551556555/I-Remember-Lemuria-And-The-Return-Of-Sathanas-Forgotten-Books-by-Richard-S-Shaver.pdf
    • http://ieuicufioao.myhome.cx/7555557552555553/War-Over-Lemuria-Richard-Shaver-Ray-Palmer-and-the-Strangest-Chapter-of-1940s-Science-Fiction-by-Richard-Toronto.pdf
    • http://ieuicufioao.myhome.cx/3556558554558553/The-Last-of-the-Doughboys-The-Forgotten-Generation-and-Their-Forgotten-World-War-by-Richard-Rubin.pdf
    • http://ieuicufioao.myhome.cx/8555559558557552/The-Last-of-the-Doughboys-The-Forgotten-Generation-and-Their-Forgotten-World-War-by-Richard-Rubin.pdf
    • http://ieuicufioao.myhome.cx/4553552554557559/The-Last-of-the-Doughboys-The-Forgotten-Generation-and-Their-Forgotten-World-War-by-Richard-Rubin.pdf
    • http://ieuicufioao.myhome.cx/2558550555558557/The-Lost-Books-of-the-Bible-and-the-Forgotten-Books-of-Eden-by-Rutherford-H-Platt-Jr-.pdf
    • http://ieuicufioao.myhome.cx/1551552551558557559/Return-of-the-Forgotten-Mouseheart-3-by-Lisa-Fiedler.pdf
    • http://ieuicufioao.myhome.cx/2550554558551551/Koreans-to-Remember-by-Richard-Saccone.pdf
    • http://ieuicufioao.myhome.cx/6558550552550558/Works-by-Richard-Matheson-Novels-by-Richard-Matheson-Screenplays-by-Richard-Matheson-Short-Stories-by-Richard-Matheson-by-Books-LLC.pdf
    • http://ieuicufioao.myhome.cx/1550555550557553559/Peter-Schlemihl-in-America-by-Forgotten-Books.pdf
    • http://ieuicufioao.myhome.cx/3559556555552553/The-Destruction-of-Da-Derga-s-Hostel-Forgotten-Books-by-Anonymous.pdf
    • http://ieuicufioao.myhome.cx/7556554556559556/Isis-Unveiled-Vol-1-of-2-Forgotten-Books-by-Helena-Petrovna-Blavatsky.pdf
    • http://ieuicufioao.myhome.cx/9558557554555556/Forgotten-Roots-by-Richard-Whitten-Barnes.pdf
    • http://ieuicufioao.myhome.cx/2551557557551557/Web-of-Deceit-Forgotten-Legacy-3-by-Richard-S-Tuttle.pdf
    • http://ieuicufioao.myhome.cx/5552559552559/The-Shadow-of-the-Wind-The-Cemetery-of-Forgotten-Books-1-by-Carlos-Ruiz-Zaf-n.pdf
    • http://ieuicufioao.myhome.cx/2551551552550551/Sensational-Prison-Escapes-From-the-Oregon-State-Penitentiary-by-Forgotten-Books.pdf
    • http://ieuicufioao.myhome.cx/2553550556555554/The-Adventures-Of-Baron-Munchausen-Forgotten-Books-by-Rudolf-Erich-Raspe.pdf
    • http://ieuicufioao.myhome.cx/6551551558556/The-Shadow-of-the-Wind-The-Cemetery-of-Forgotten-Books-1-by-Carlos-Ruiz-Zaf-n.pdf
    • http://ieuicufioao.myhome.cx/3554553552557551/The-Life-of-Merlin-Vita-Merlini-Forgotten-Books-by-Geoffrey-of-Monmouth.pdf
    • http://ieuicufioao.myhome.cx/1555556551553552/Shadowdale-Forgotten-Realms-Avatar-1-by-Richard-Awlinson.pdf
    • http://ieuicufioao