Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba86c1f82b84828a…

MALICIOUS

PDF

19.2 KB Created: 2020-03-18 21:14:35 +00:00 Authoring application: mPDF 5.7
MD5: 853527194aa9f87068fa7827558f0ad0 SHA-1: 30473986b12beaecc0b44ff19de02d00f004018d SHA-256: ba86c1f82b84828a6fd346f9b22dd2dde1bc6f73d4909c1a8425ee0baf755a8a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The document body, though heavily obfuscated, contains numerous URLs pointing to external resources, suggesting a link farm or distribution point for further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/4c04c08c09c05c08/Adding-it-Up-By-the-Numbers-2-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/3c01c05c01c04c09/The-Numbers-Game-Why-Everything-You-Know-About-Soccer-Is-Wrong-by-Chris-Anderson.pdf
    • http://laoieoa.myhome.cx/2c01c03c01c08c01/Adagio-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/3c04c07c09c06c09/Light-Touch-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/3c04c07c08c05c02/Bad-Pennies-Bareback-1-5-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/4c01c08c06c03c06/Natural-Disaster-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/4c04c07c08c06c08/Domination-Deviations-2-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/2c02c04c03c08c07/Rough-Draft-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/4c04c08c00c02c08/An-Agreement-Among-Gentlemen-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/2c03c03c00c06c01/Journey-from-Obscurity-Wilfred-Owen-1893-1918-Memoirs-of-the-Owen-Family-1-Childhood-by-Harold-Owen.pdf
    • http://laoieoa.myhome.cx/1c06c03c02c02c06/Numbers-Numbers-1-by-Rachel-Ward.pdf
    • http://laoieoa.myhome.cx/3c03c03c02c08c01/Never-Too-Early-The-Beginning-Never-Too-Early-1-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/2c05c05c03c01c09/Bareback-Bareback-1-by-Chris-Owen.pdf
    • http://laoieoa.myhome.cx/5c09c00c04c08c02/Adding-To-The-Family-by-Gina-Wilkins.pdf
    • http://laoieoa.myhome.cx/1c08c07c01c05/Wheel-Thrown-Ceramics-Altering-Trimming-Adding-Finishing-by-Don-Davis.pdf
    • http://laoieoa.myhome.cx/6c04c02c01c04/Adding-Fire-to-the-Fuel-Challenging-Shame-and-the-Stigma-of-Alcoholism-by-Scott-Stevens.pdf
    • http://laoieoa.myhome.cx/1c00c06c07c05c07c05/Johann-Owen-s-Reisen-Durch-Verschiedene-Lander-Und-Gegenden-Von-Europa-in-Den-Jezt-Verflossenen-Jahren-Mit-Vertraulichen-Bemerkungen-Uber-Orte-Menschen-Und-Sitten-Zugleich-in-Jezigen-Zeit-Umstande-by-John-Owen.pdf
    • http://laoieoa.myhome.cx/9c09c02c05c02c06/Electronics-for-Artists-Adding-Light-Motion-and-Sound-to-Your-Artwork-by-Simon-Quellen-Field.pdf
    • http://laoieoa.myhome.cx/3c07c09c04c04c07/The-Body-of-Chris-A-Memoir-of-Obsession-Addiction-and-Madness-by-Chris-Cole.pdf
    • http://laoieoa.myhome.cx/3c06c08c00c03c08/By-the-Numbers-by-K-D-West.pdf
    • http://laoieoa.myhome.cx/2c03c03c00c06c01/Journey-fro