Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1fd4e519d436705…

MALICIOUS

PDF

24.3 KB Created: 2020-03-18 18:26:45 +00:00 Authoring application: mPDF 5.7
MD5: e4731da3fb579fedf8a2532fc7f77885 SHA-1: 7b7ad989eb7faf881ef91691de1561e3f69a54c7 SHA-256: b1fd4e519d436705f7cee618ad5864642d759ca41d804d71941152f2976f4a4c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary purpose appears to be directing users to a multitude of external websites, likely for SEO poisoning or to host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/6622628626623623/The-Paris-Game-Charles-de-Gaulle-the-Liberation-of-Paris-and-the-Gamble-that-Won-France-by-Ray-Argyle.pdf
    • http://weisncio.myhome.cx/1620629626623621628/Wissenschaft-Paris-Bildung-in-Paris-Forschung-in-Paris-Institut-de-France-Foucaultsches-Pendel-Academie-Francaise-by-Quelle-Wikipedia.pdf
    • http://weisncio.myhome.cx/1620626620625620626/Sport-Paris-Fussballverein-Aus-Paris-Sportstatte-in-Paris-Sportveranstaltung-in-Paris-Sportverein-Paris-Olympische-Sommerspiele-1900-by-Quelle-Wikipedia.pdf
    • http://weisncio.myhome.cx/6621621620621628/From-Here-To-Paris---Get-laid-off-Buy-a-barge-in-France-Take-it-to-Paris-by-Cris-Hammond.pdf
    • http://weisncio.myhome.cx/1620629626623621629/Bildung-Und-Forschung-in-Der-Ile-de-France-Hochschullehrer-Versailles-Museum-in-Paris-Wissenschaft-Paris-Louvre-Foucaultsches-Pendel-by-Quelle-Wikipedia.pdf
    • http://weisncio.myhome.cx/1620623624625627627/Bahnhof-in-Frankreich-Bahnhof-in-Paris-Rer-Bahnhof-Ile-de-France-Bahnhof-Strasbourg-Bahnhof-Metz-Gare-Montparnasse-Paris-Gare-Du-Nord-by-Quelle-Wikipedia.pdf
    • http://weisncio.myhome.cx/6622628625622622/The-General-Charles-De-Gaulle-And-The-France-He-Saved-by-Jonathan-Fenby.pdf
    • http://weisncio.myhome.cx/1620621626625626627/The-Blood-of-Free-Men-The-Liberation-of-Paris-1944-by-Michael-S-Neiberg.pdf
    • http://weisncio.myhome.cx/3624626627620/Paris-Connections-African-American-Artists-In-Paris-by-Asake-Bomani.pdf
    • http://weisncio.myhome.cx/5623624622624625/Contemporary-Living-in-Paris-Demeures-Contemporaines-a-Paris-Hendendaags-Wonen-in-Parijs-by-Wim-Pauwels.pdf
    • http://weisncio.myhome.cx/6622629627623623/The-Civil-War-in-France-The-Paris-Commune-by-Karl-Marx.pdf
    • http://weisncio.myhome.cx/8626625628620620/Orpheus-in-Paris-Offenbach-and-the-Paris-of-His-Time-by-Siegfried-Kracauer.pdf
    • http://weisncio.myhome.cx/6622629626621627/Paris-Babylon-The-Story-of-the-Paris-Commune-by-Rupert-Christiansen.pdf
    • http://weisncio.myhome.cx/4623626625626623/Paris-Paris-Journey-into-the-City-of-Light-by-David-Downie.pdf
    • http://weisncio.myhome.cx/1621627625625624/Paris-Paris-Journey-into-the-City-of-Light-by-David-Downie.pdf
    • http://weisncio.myhome.cx/5628622624621626/Paris-A-World-Heritage-Site-Travel-Guide-Paris-Banks-of-the-Seine---2017-by-J-r-me-Sabatier.pdf
    • http://weisncio.myhome.cx/1620626620624629628/Sportveranstaltung-in-Paris-Olympische-Sommerspiele-1900-Paris-Roubaix-Leichtathletik-Halleneuropameisterschaft-2011-by-Quelle-Wikipedia.pdf
    • http://weisncio.myhome.cx/9628628623624625/France-at-Bay-1870-1871-The-Struggle-for-Paris-by-Douglas-Fermer.pdf
    • http://weisncio.myhome.cx/5622629625623622/When-Paris-Sizzled-The-1920s-Paris-of-Hemingway-Chanel-Cocteau-Cole-Porter-Josephine-Baker-and-Their-Friends-by-Mary-McAuliffe.pdf
    • http://weisncio.myhome.cx/2629625624620622/Pancakes-in-Paris-Living-the-American-Dream-in-France-by-Craig-Carlson.pdf
    • http://weisncio.myhome.cx/1620629626623621629/Bildung-Und-Forschung-in-Der-Ile-de-France-Ho