Malicious PDF — malware analysis report

Static analysis result for SHA-256 a75569037e8d5436…

MALICIOUS

PDF

21.5 KB Created: 2020-02-14 22:44:46 +00:00 Authoring application: mPDF 5.7
MD5: 3360496c501ba9d7fbebcc89d89dae1f SHA-1: 7e64a647636db474a7000d81742d6bc80a3669b3 SHA-256: a75569037e8d54366fb2a3e658280db4155b4dda1fc0a7c3b8d1741ab1470287
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external URLs, a technique often used for SEO poisoning or to redirect users to malicious sites. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, such as http://weisncio.myhome.cx/4620621623620626/Three-Musketeers-by-Alexandre-Dumas.pdf, are likely part of a link farm designed to manipulate search engine rankings or distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/4620621623620626/Three-Musketeers-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/1621625627622629622/Three-Musketeers-special-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/1620625626628624621/Three-Musketeers-The-Classic-Collection-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/8621627621629625/The-Three-Musketeers-Annotated-with-short-biography-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/8620626628621628/The-Three-Musketeers-In-Easy-To-Read-Type-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/7622622627623625/The-Three-Musketeers-Ad-Classic-Library-Edition-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/5622626627626625/The-Three-Musketeers-with-over-two-hundred-illustrations-by-Maurice-Leloir-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/9622621628624621/The-Three-Musketeers-1000-Copy-Limited-Edition-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/6623623627625627/The-Man-In-The-Iron-Mask-By-Alexandre-Dumas-p-re-Illustrated-amp-Unabridged-Free-Bonus-Audiobook-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/5625626627620620/Le-Comte-de-Monte-Cristo-oeuvre-complete-annot-e-par-Alexandre-Dumas-p-re-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/6623623627622629/The-Count-of-Monte-Cristo-Inti-Classics-Annotated-by-Alexandre-Dumas-p-re-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/7623622625620626/La-Dame-de-Monsoreau---Tome-1-amp-2-amp-3---Alexandre-Dumas---Roman-historique---annot-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/8620629629624623/Les-trois-mousquetaires-le-vicomte-de-Bragelonne-complet-et-annot-Alexandre-Dumas-t-3-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/6623626623622624/The-Works-of-Alexandre-Dumas-the-Vicomte-de-Bragelonne-Part-One-Volume-3-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/1621627626624620628/The-Works-of-Alexandre-Dumas-Vol-2-of-30-The-Count-Of-Monte-Cristo-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/1620629628620625627/The-Count-of-Monte-Cristo-By-Alexandre-Dumas---Rank-30-Of-100-100-Formatted-Wordwise-Enabled-Active-TOC-Active-Footnotes-Illustrated--JKL-Classics-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/5624627624626621/The-Cenci-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/9627620622620627/Die-Bartholom-usnacht-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/8625622628627628/Murat-by-Alexandre-Dumas.pdf
    • http://weisncio.myhome.cx/1620624629625624628/Les-trois-mousquetaires-by-Alexandre-Dumas.pdf