Malicious PDF — malware analysis report

Static analysis result for SHA-256 b07fd7d5e792e3b5…

MALICIOUS

PDF

18.5 KB Created: 2020-03-13 23:58:49 +00:00 Authoring application: mPDF 5.7
MD5: 97e46ae58fc6a28b837af7d06986d481 SHA-1: d8ba6d129609c1cf16f0b221346df7eff51c2af4 SHA-256: b07fd7d5e792e3b5bb080f165246114818140f79b4ed2e378518e470c48a0a98
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or distributing malicious content. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the embedded URLs suggest a malicious intent to redirect the user to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/6552558559558558/Murder-on-Lenox-Hill-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/2552551558551551/Murder-on-Sisters-Row-Gaslight-Mystery-13-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/3552551551558555/Murder-on-Waverly-Place-Gaslight-Mystery-11-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/2550551557554554/Murder-on-Bank-Street-Gaslight-Mystery-10-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/6552558559555556/Murder-on-Astor-Place-Gaslight-Mystery-1-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/4552557551552558/Murder-on-Trinity-Place-Gaslight-Mystery-22-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/3552551551556557/Murder-on-Lexington-Avenue-Gaslight-Mystery-12-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/4557555551552552/A-Year-at-Mulberry-Cottage-Mulberry-Cottage-2-by-Victoria-Connelly.pdf
    • http://ieuicufioao.myhome.cx/9556555550556/Michael-Patrick-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/6553559558559552/Mord-in-Greenwich-Village-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/6559554551/City-of-Lies-Counterfeit-Lady-1-by-Victoria-Thompson.pdf
    • http://ieuicufioao.myhome.cx/7559555554557558/Murder-at-the-Bijou-by-Jim-Thompson.pdf
    • http://ieuicufioao.myhome.cx/9555556557555551/Corbin-s-Bend-Season-Two-Second-Collection-Corbin-s-Bend-Box-Set-Book-2-by-Tara-Finnegan.pdf
    • http://ieuicufioao.myhome.cx/1550555554553554/A-Vision-of-Murder-Psychic-Eye-Mystery-3-by-Victoria-Laurie.pdf
    • http://ieuicufioao.myhome.cx/3552554551554558/Eight-Weeks-in-the-Summer-of-Victoria-s-Jubilee-The-Queen-the-Jews-and-a-Murder-by-Bob-Biderman.pdf
    • http://ieuicufioao.myhome.cx/1550555550552558556/River-Bend-The-Series-River-Bend-1-3-by-Molly-McLain.pdf
    • http://ieuicufioao.myhome.cx/8553551550550/Silk-Stalkings-When-Women-Write-of-Murder-A-Survey-of-Series-Characters-Created-by-Women-Authors-in-Crime-and-Mystery-Fiction-by-Victoria-Nichols.pdf
    • http://ieuicufioao.myhome.cx/1558557556555554/Once-Upon-a-Mulberry-Field-by-C-L-Hoang.pdf
    • http://ieuicufioao.myhome.cx/5553555554554557/Mulberry-by-Paulette-Boudreaux.pdf
    • http://ieuicufioao.myhome.cx/1551554557552554557/Thompson-amp-Thompson-Genetics-in-Medicine-with-Student-Consult-Online-Access-by-Robert-L-Nussbaum.pdf