Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f97b2ccccb7b38d…

MALICIOUS

PDF

16.7 KB Created: 2020-03-19 01:20:47 +00:00 Authoring application: mPDF 5.7
MD5: e42f9d8c231e6b8031a159201915333a SHA-1: ce7cbfe733f459089d6fe7af73c20f220733e72a SHA-256: 9f97b2ccccb7b38d810b93ca777e3efc71865c14c5bad27ae61508896191b0f2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple heuristics as malicious, including a critical finding for a link farm containing 22 external PDF links. The embedded links, such as http://weisncio.myhome.cx/1625622621624628/Claimed-by-the-Alphas-Shifters-of-Appalachia-Book-1-by-Viola-Rivard.pdf, are likely used to distribute further malware or phishing content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7649173-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7649173-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1625622621624628/Claimed-by-the-Alphas-Shifters-of-Appalachia-Book-1-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620625622621621624/Claimed-by-the-Alphas-Part-Three-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624624620621624/Home-Running-With-Alphas-7-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620625622621626620/Choices-Running-With-Alphas-3-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624622625627622/Faith-Running-With-Alphas-5-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620629624622628623/Grizzly-Bear-s-Bride-Greystone-Shifters-1-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624622625627623/Taming-the-Alpha-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620625622621620628/Bound-to-the-Alpha-Part-One-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4629623623629623/The-Dragon-s-Appraiser-Part-Three-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1628627629620628/Etienne-The-Shifters-of-Shotgun-Row-Book-1-by-Ever-Coming.pdf
    • http://weisncio.myhome.cx/1628624625622621/Nessa-s-Two-Shifters-Wolf-s-Pass-Shifters-1-by-Marla-Monroe.pdf
    • http://weisncio.myhome.cx/3622624628629628/Through-The-Cat-s-Eyes-2nd-Chance-Shifters-Book-1-by-Margaret-Taylor.pdf
    • http://weisncio.myhome.cx/3622624621629627/Demons-Shifters-and-Witches-Oh-My-4-Paranormal-Book-Bundle-by-4-Amazon-Best-Selling-Authors-by-Elizabeth-A-Reeves.pdf
    • http://weisncio.myhome.cx/2629627622621627/The-Kategan-Alphas-Vol-1-The-Kategan-Alphas-1--3-by-T-A-Grey.pdf
    • http://weisncio.myhome.cx/2626628626621629/Claimed-by-the-Elven-King-The-Complete-Edition-Elven-King-Series-Book-1-by-Cristina-Rayne.pdf
    • http://weisncio.myhome.cx/3622627624626629/Outlaw-Alpha-Witches-Shifters-Bikers-Paranormal-Romantic-Mystery-Thriller-Fangs-of-Anarchy-Book-2-by-Nina-Blackman.pdf
    • http://weisncio.myhome.cx/2629623627628620/Claimed-by-the-Billionaire-2-Claimed-by-the-Billionaire-2-by-Ann-King.pdf
    • http://weisncio.myhome.cx/2629623627627629/Claimed-by-the-Billionaire-4-Claimed-by-the-Billionaire-4-by-Ann-King.pdf
    • http://weisncio.myhome.cx/2629623627627628/Claimed-by-the-Billionaire-3-Claimed-by-the-Billionaire-3-by-Ann-King.pdf
    • http://weisncio.myhome.cx/3623623625623624/The-Littlest-Assassin-Shifters-Assassin-Shifters-18-by-Sandrine-Gasq-Dion.pdf
    • http://weisncio.myhome.cx/362262462862