Malicious PDF — malware analysis report

Static analysis result for SHA-256 a16306f039009fe2…

MALICIOUS

PDF

19.7 KB Created: 2020-03-13 09:01:37 +00:00 Authoring application: mPDF 5.7
MD5: 6f3b370431bd2d33d6b1137b8d61e86e SHA-1: faa9d3a4be75da355d1736449bb30f8c6efe9e1b SHA-256: a16306f039009fe2e0d1715f59407e5e740cacbf9c4159fdd35711345d7788a0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by an ML classifier as malicious and contains a large number of embedded links to external PDF files. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm, with the first URL being http://laoieoa.myhome.cx/1c01c01c03c02c03c08/The-Terrorist-by-Barry-Levy.pdf. This suggests the document's primary purpose is to redirect users to potentially harmful content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/1c01c01c03c02c03c08/The-Terrorist-by-Barry-Levy.pdf
    • http://laoieoa.myhome.cx/1c01c01c03c06c03c09/Terrorist-Recognition-Handbook-A-Practitioner-s-Manual-for-Predicting-and-Identifying-Terrorist-Activities-by-Malcolm-W-Nance.pdf
    • http://laoieoa.myhome.cx/9c03c08c08c06c08/Levy-Matters-III-Levy-Type-Processes-Construction-Approximation-and-Sample-Path-Properties-by-Bj-rn-B-ttcher.pdf
    • http://laoieoa.myhome.cx/6c08c08c03c07c05/The-Wonderful-World-Of-Barry-Mc-Kenzie-by-Barry-Humphries.pdf
    • http://laoieoa.myhome.cx/3c04c09c01c01c00/Live-Right-and-Find-Happiness-Although-Beer-is-Much-Faster-Life-Lessons-and-Other-Ravings-from-Dave-Barry-by-Dave-Barry.pdf
    • http://laoieoa.myhome.cx/7c05c03c00c07c00/Barry-Trotter-and-the-Unnecessary-Sequel-The-Book-Nobody-Has-Been-Waiting-for-Barry-Trotter-2-by-Michael-Gerber.pdf
    • http://laoieoa.myhome.cx/3c08c05c07c08c07/Dave-Barry-s-Money-Secrets-Like-Why-Is-There-a-Giant-Eyeball-on-the-Dollar-by-Dave-Barry.pdf
    • http://laoieoa.myhome.cx/2c07c04c09c07c05/You-Can-Date-Boys-When-You-re-Forty-Dave-Barry-on-Parenting-and-Other-Topics-He-Knows-Very-Little-About-by-Dave-Barry.pdf
    • http://laoieoa.myhome.cx/8c01c01c05c07/Dave-Barry-Slept-Here-A-Sort-of-History-of-the-United-States-by-Dave-Barry.pdf
    • http://laoieoa.myhome.cx/4c03c05c07c02/Terrorist-by-John-Updike.pdf
    • http://laoieoa.myhome.cx/1c03c09c07c05c03/Counter-Terrorist-by-Sam-Hall.pdf
    • http://laoieoa.myhome.cx/1c00c05c07c00c02c00/How-Lon-Got-Screwed-by-a-Terrorist-by-E-K-Barone.pdf
    • http://laoieoa.myhome.cx/1c04c07c03c03c00/Jimmy-The-Terrorist-by-Omair-Ahmad.pdf
    • http://laoieoa.myhome.cx/7c00c08c04c04c01/The-Black-Terrorist-by-Tierno-Mon-nembo.pdf
    • http://laoieoa.myhome.cx/1c02c07c03c07c03/The-Dangers-of-Islam-The-Terrorist-by-Helena-Won.pdf
    • http://laoieoa.myhome.cx/5c05c03c06c01c00/The-Unknown-Terrorist-by-Richard-Flanagan.pdf
    • http://laoieoa.myhome.cx/1c04c03c02c07c06/The-Unknown-Terrorist-by-Richard-Flanagan.pdf
    • http://laoieoa.myhome.cx/5c00c09c04c03/The-Unseen-Terrorist-by-Oche-Otorkpa.pdf
    • http://laoieoa.myhome.cx/9c07c05c03c06/The-Terrorist-s-Son-A-Story-of-Choice-by-Zak-Ebrahim.pdf
    • http://laoieoa.myhome.cx/9c08c07c03c00c09/The-Buddha-and-the-Terrorist-by-Satish-Kumar.pdf
    • http://laoieoa.myhome.cx/7c05c03c00c07c00/Barry-Trotter-and-the-Unnecessary-Sequ