Malicious PDF — malware analysis report

Static analysis result for SHA-256 af51f073c6400f80…

MALICIOUS

PDF

18.7 KB Created: 2020-02-16 05:30:15 +00:00 Authoring application: mPDF 5.7
MD5: 4c9cd43b2640702a454449ab5177ec5c SHA-1: b8f24ee6fa1f0cde81329acf90db493f9538f2f8 SHA-256: af51f073c6400f8002c8824566270e4e08eaa06e6fc498e958bd142a0b65d6fe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'peldoaio.myhome.cx'. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic to malicious or low-quality content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://peldoaio.myhome.cx/13d13d83d53d63d7/How-To-Cook-A-Moose-by-Kate-Christensen.pdf
    • http://peldoaio.myhome.cx/63d13d43d13d3/The-Epicure-s-Lament-by-Kate-Christensen.pdf
    • http://peldoaio.myhome.cx/43d33d63d73d23d1/Blue-Plate-Special-An-Autobiography-of-My-Appetites-by-Kate-Christensen.pdf
    • http://peldoaio.myhome.cx/83d33d63d23d23d4/The-Innovator-s-Dilemma-When-New-Technologies-Cause-Great-Firms-to-Fail-by-Clayton-M-Christensen.pdf
    • http://peldoaio.myhome.cx/13d63d83d83d63d9/Lithochronos-Ou-Le-Premier-Vol-de-La-Pierre-Autour-de-Quinze-Photographies-D-Andree-Christensen-by-Andr-e-Christensen.pdf
    • http://peldoaio.myhome.cx/83d43d43d43d83d3/Great-Joy-by-Kate-DiCamillo.pdf
    • http://peldoaio.myhome.cx/43d63d03d63d63d9/Fantastically-Great-Women-Who-Changed-the-World-by-Kate-Pankhurst.pdf
    • http://peldoaio.myhome.cx/13d83d93d43d03d8/The-Great-Unconformity-Reflections-on-Hope-in-an-Imperiled-World-by-Kate-Troll.pdf
    • http://peldoaio.myhome.cx/23d83d83d63d23d2/The-Suspicions-Of-Mr-Whicher-A-Murder-And-The-Undoing-Of-A-Great-Victorian-Detective-by-Kate-Summerscale.pdf
    • http://peldoaio.myhome.cx/13d63d93d43d43d7/California-Holiday-Or-How-the-World-s-Worst-Summer-Job-Gave-Me-a-Great-New-Life-by-Kate-Cann.pdf
    • http://peldoaio.myhome.cx/83d03d63d83d33d3/The-Clayton-M-Christensen-Reader-by-Clayton-M-Christensen.pdf
    • http://peldoaio.myhome.cx/83d43d13d33d1/Works-by-Kate-Chopin-Novels-by-Kate-Chopin-Short-Stories-by-Kate-Chopin-Desiree-s-Baby-the-Awakening-the-Storm-the-Story-of-an-Hour-by-Books-LLC.pdf
    • http://peldoaio.myhome.cx/53d13d63d63d33d1/it-by-Inger-Christensen.pdf
    • http://peldoaio.myhome.cx/23d53d43d83d63d9/alphabet-by-Inger-Christensen.pdf
    • http://peldoaio.myhome.cx/43d13d13d33d6/Django-by-Bonnie-Christensen.pdf
    • http://peldoaio.myhome.cx/83d03d63d93d23d2/Impact-by-Andreas-Christensen.pdf
    • http://peldoaio.myhome.cx/33d53d63d03d23d8/The-Tome-by-Troy-Christensen.pdf
    • http://peldoaio.myhome.cx/63d73d13d53d2/alphabet-by-Inger-Christensen.pdf
    • http://peldoaio.myhome.cx/33d53d13d63d63d8/The-Truth-About-Dating-by-Julie-Christensen.pdf
    • http://peldoaio.myhome.cx/83d23d23d83d33d4/29-Tekster-Fra-Februar-by-Vagner-Boe-Christensen.pdf
    • http://peldoaio.myhome.cx/13d83d93d43d03d8/The-Great-Unconformity-Re