Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9b91257d8c0a8a4…

MALICIOUS

PDF

28.1 KB Created: 2020-03-18 17:41:44 +00:00 Authoring application: mPDF 5.7
MD5: 6ae423ed074ec519d97753dac6d85ace SHA-1: 1e2314800402c87cda4ec498522d7c7a0ddaefba SHA-256: b9b91257d8c0a8a4655a5e7215235a7abb1e61877912a7c564e02dcf7db701d6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified by the 'PDF_SEO_LINK_FARM' heuristic, pointing to external PDF files hosted on 'tikytsesapdf.myhome.cx'. This suggests a link farm or redirection scheme designed to lead users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9742

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tikytsesapdf.myhome.cx/678c578c378c578c4/Donald-Duck-Comics-Donald-Duck-Comics-by-Carl-Barks-Donald-Duck-Comics-by-Don-Rosa-the-Life-and-Times-of-Scrooge-McDuck-by-Source-Wikipedia.pdf
    • http://tikytsesapdf.myhome.cx/278c678c578c678c278c3/Uncle-Scrooge-and-Donald-Duck-Return-to-Plain-Awful-The-Don-Rosa-Library-2-by-Don-Rosa.pdf
    • http://tikytsesapdf.myhome.cx/278c478c278c578c2/Uncle-Scrooge-and-Donald-Duck-The-Son-of-the-Sun-The-Don-Rosa-Library-1-by-Don-Rosa.pdf
    • http://tikytsesapdf.myhome.cx/278c478c278c078c978c8/Donald-Duck-A-Christmas-for-Shacktown-The-Carl-Barks-Library-11-by-Carl-Barks.pdf
    • http://tikytsesapdf.myhome.cx/478c478c278c978c978c9/Donald-Duck-Lost-in-the-Andes-The-Carl-Barks-Library-7-by-Carl-Barks.pdf
    • http://tikytsesapdf.myhome.cx/478c478c178c478c378c1/Walt-Disney-s-Donald-Duck-Adventures-The-Golden-Helmet-Gladstone-Comic-Album-Series-No-13-by-Carl-Barks.pdf
    • http://tikytsesapdf.myhome.cx/278c178c078c178c078c4/Donald-Duck-Adventures-20-by-Michael-T-Gilbert.pdf
    • http://tikytsesapdf.myhome.cx/178c078c978c478c078c078c8/Focus-On-100-Most-Popular-Fictional-Adoptees-Jessica-Jones-Iron-Man-Princess-Leia-Quicksilver-comics-Havok-comics-Jon-Snow-character-Uhtred-Krueger-Rogue-comics-Hellboy-etc-by-Wikipedia-contributors.pdf
    • http://tikytsesapdf.myhome.cx/278c378c978c478c9/The-Life-and-Times-of-Scrooge-McDuck-by-Don-Rosa.pdf
    • http://tikytsesapdf.myhome.cx/478c478c178c878c078c3/The-Life-and-Times-of-Scrooge-McDuck-Companion-by-Don-Rosa.pdf
    • http://tikytsesapdf.myhome.cx/378c578c278c678c978c6/Duck-Duck-Ghost-Hellsinger-2-by-Rhys-Ford.pdf
    • http://tikytsesapdf.myhome.cx/678c978c778c578c678c7/Duck-Duck-Dinosaur-by-Kallie-George.pdf
    • http://tikytsesapdf.myhome.cx/678c478c678c178c178c2/Secret-Comics-Japan-Underground-Comics-Now-by-Hyoe-Narita.pdf
    • http://tikytsesapdf.myhome.cx/778c678c978c578c478c8/Pekin-Ducks-as-Pets-American-Pekin-Duck-Owner-s-Manual-American-Pekin-Duck-Pros-and-Cons-Care-Housing-Diet-and-Health-All-Included-by-Roland-Ruthersdale.pdf
    • http://tikytsesapdf.myhome.cx/878c478c678c578c278c2/Uncle-Scrooge-The-Seven-Cities-of-Gold-The-Carl-Barks-Library-14-by-Carl-Barks.pdf
    • http://tikytsesapdf.myhome.cx/778c578c778c178c178c5/Toronto-Comics-Anthology-Toronto-Comics-1-by-Steven-Andrews.pdf
    • http://tikytsesapdf.myhome.cx/178c078c578c478c778c978c9/Comics-Squad-2-Lunch-Comics-Squad-2-by-Matthew-Holm.pdf
    • http://tikytsesapdf.myhome.cx/978c278c278c178c278c3/Archie-1000-Page-Comics-Digest-by-Archie-Comics.pdf
    • http://tikytsesapdf.myhome.cx/778c578c778c178c578c2/Toronto-Comics-Volume-3-Toronto-Comics-3-by-Steven-Andrews.pdf
    • http://tikytsesapdf.myhome.cx/678c678c178c278c078c4/Articles-on-French-Comics-Writers-Including-Ren-Goscinny-Enki-Bilal-Jacques-Tardi-Alejandro-Jodorowsky-Sylvain-Chomet-Joann-Sfar-Jacques-Martin-Comics-Fran-OIS-Bourgeon-Emmanuel-Larcenet-David-Beauchard-Lewis-Trondheim-by-Hephaestus-Books.pdf
    • http://tikytsesapdf.myhome.cx/278c478c278c078c978c8/Donald-Du