Malicious PDF — malware analysis report

Static analysis result for SHA-256 b50c3254bc08428c…

MALICIOUS

PDF

18.8 KB Created: 2020-03-20 02:09:35 +00:00 Authoring application: mPDF 5.7
MD5: ba9096720c451d758eeda143d5335e4b SHA-1: 57c3f99756aeecac9c0f2c78ee2869124a4a6dc8 SHA-256: b50c3254bc08428c896ec1c423a8eeb667ad45edf5985dd78b74892e0d404633
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'laoieoa.myhome.cx'. This is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/8c00c00c05c09c05/Pastorale-by-Deborah-Eisenberg.pdf
    • http://laoieoa.myhome.cx/1c00c06c04c01c05c06/The-Stories-by-Deborah-Eisenberg.pdf
    • http://laoieoa.myhome.cx/1c00c06c04c01c09c01/Your-Duck-Is-My-Duck-Stories-by-Deborah-Eisenberg.pdf
    • http://laoieoa.myhome.cx/1c00c06c04c02c06c06/The-Jesse-Eisenberg-Handbook---Everything-You-Need-to-Know-about-Jesse-Eisenberg-by-Victoria-Moses.pdf
    • http://laoieoa.myhome.cx/6c07c00c06c03c07/The-101st-Airborne-at-Normandy-by-Mark-A-Bando.pdf
    • http://laoieoa.myhome.cx/7c08c08c06c09c05/Airborne-and-Terrestrial-Laser-Scanning-by-George-Vosselman.pdf
    • http://laoieoa.myhome.cx/6c05c08c09c03c03/Recondo-LRRPs-in-the-101st-Airborne-by-Larry-Chambers.pdf
    • http://laoieoa.myhome.cx/2c02c03c06c05c06/Airborne-A-Photobiography-of-Wilbur-and-Orville-Wright-by-Mary-Collins.pdf
    • http://laoieoa.myhome.cx/6c07c00c06c02c04/101st-Airborne-The-Screaming-Eagles-in-World-War-II-by-Mark-Bando.pdf
    • http://laoieoa.myhome.cx/1c01c05c08c03c09c06/AWACS-and-Hawkeyes-The-Complete-History-of-Airborne-Early-Warning-Aircraft-by-Edwin-Armistead.pdf
    • http://laoieoa.myhome.cx/3c08c03c05c07c01/Utah-Beach-The-Amphibious-Landing-and-Airborne-Operations-on-D-Day-June-6-1944-by-Joseph-Balkoski.pdf
    • http://laoieoa.myhome.cx/1c00c06c04c02c00c00/The-Revisionist-by-Jesse-Eisenberg.pdf
    • http://laoieoa.myhome.cx/1c00c06c04c01c05c00/The-Age-of-Eisenberg-by-Andrew-Bellamy.pdf
    • http://laoieoa.myhome.cx/8c09c04c05c04c00/Descending-from-the-Clouds-A-Memoir-of-Combat-in-the-505-Parachute-Infantry-Regiment-82d-Airborne-Division-by-Spencer-F-Wurst.pdf
    • http://laoieoa.myhome.cx/8c09c04c02c09c04/Descending-from-the-Clouds-A-Memoir-of-Combat-in-the-505-Parachute-Infantry-Regiment-82d-Airborne-Division-by-Spencer-Wurst.pdf
    • http://laoieoa.myhome.cx/1c00c06c04c03c04c06/Sams-Teach-Yourself-WPF-in-24-Hours-by-Rob-Eisenberg.pdf
    • http://laoieoa.myhome.cx/1c09c09c01c02c09/A-Trouble-Halved-by-Andy-Eisenberg.pdf
    • http://laoieoa.myhome.cx/8c04c06c01c02c02/-tudes-for-Elixir-by-J-David-Eisenberg.pdf
    • http://laoieoa.myhome.cx/4c03c04c06c02c07/Unexpected-Guest-by-Andy-Eisenberg.pdf
    • http://laoieoa.myhome.cx/6c06c09c04c04c00/Testament-de-Moise-by-Josy-Eisenberg.pdf
    • http://laoieoa.myhome.cx/6c07c00c06c02c04/101st-Airborne-The-Screaming-Eagles-in-W