Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf291bdf2a68256a…

MALICIOUS

PDF

19.7 KB Created: 2020-03-14 00:57:29 +00:00 Authoring application: mPDF 5.7
MD5: 0c49322195582ea1ed25f8ba3e399e95 SHA-1: af630786eb46d466219b067714f9768718f98ebd SHA-256: bf291bdf2a68256ad59020d68e3aa1805cc6833b6a02065f0588b6ea6205991f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly indicated maliciousness. The primary attack pattern appears to be a link farm, likely intended to manipulate search engine results or distribute malware via the linked PDFs. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eascasas.myhome.cx/6aa3aa7aa3aa9aa5/Francisco-de-Miranda-A-Transatlantic-Life-in-the-Age-of-Revolution-by-Karen-Racine.pdf
    • http://eascasas.myhome.cx/2aa0aa1aa2aa7aa2/Francisco-de-Miranda-and-the-Revolutionizing-of-Spanish-America-by-William-Spence-Robertson.pdf
    • http://eascasas.myhome.cx/8aa5aa1aa1aa5aa3/Racine-s-Phedre-Ed-with-Introduction-and-Notes-by-Jean-Racine.pdf
    • http://eascasas.myhome.cx/6aa0aa0aa2aa4aa2/New-Transatlantic-Partnership-A-European-Perspective-on-the-Transatlantic-Partnership-for-Trade-Monetary-and-Security-Relation-by-Geoffrey-Denton.pdf
    • http://eascasas.myhome.cx/9aa8aa1aa7aa4aa3/DESPERTA-SERVUS-O-TEMPO-URGE-A-SAGA-DO-REI-DO-MUNDO-1-by-A-S-FRANCISCO-FRANCISCO.pdf
    • http://eascasas.myhome.cx/6aa2aa6aa5aa4aa2/Rizal-Life-Works-And-Ideals-by-Francisco-M-Zulueta.pdf
    • http://eascasas.myhome.cx/2aa1aa0aa8aa9aa8/At-the-Far-Reaches-of-Empire-The-Life-of-Juan-Francisco-de-la-Bodega-Y-Quadra-by-Freeman-M-Tovell.pdf
    • http://eascasas.myhome.cx/4aa7aa7aa7aa9aa9/A-Girl-s-Guide-to-Taking-Over-the-World-Writings-From-The-Girl-Zine-Revolution-by-Karen-Green.pdf
    • http://eascasas.myhome.cx/7aa6aa6aa9aa6aa6/Anarchist-Education-and-the-Modern-School-A-Francisco-Ferrer-Reader-by-Francisco-Ferrer.pdf
    • http://eascasas.myhome.cx/4aa2aa1aa0aa3aa8/Alice-Miranda-on-Holiday-Alice-Miranda-2-by-Jacqueline-Harvey.pdf
    • http://eascasas.myhome.cx/4aa8aa9aa0aa1aa6/TransAtlantic-by-Colum-McCann.pdf
    • http://eascasas.myhome.cx/1aa0aa7aa9aa2aa9aa6/Liberating-Life-Woman-s-Revolution-by-Abdullah-calan.pdf
    • http://eascasas.myhome.cx/7aa0aa6aa7aa1aa7/Revolution-of-the-Mind-The-Life-of-Andr-Breton-by-Mark-Polizzotti.pdf
    • http://eascasas.myhome.cx/6aa2aa1aa8aa4aa2/The-Murderous-Revolution-Life-and-Death-in-Pol-Pot-s-Kampuchea-by-Martin-Stuart-Fox.pdf
    • http://eascasas.myhome.cx/9aa7aa9aa9aa3aa0/The-Giant-of-the-French-Revolution-Danton-A-Life-by-David-Lawday.pdf
    • http://eascasas.myhome.cx/5aa0aa6aa9aa9aa8/Growing-a-Revolution-Bringing-Our-Soil-Back-to-Life-by-David-R-Montgomery.pdf
    • http://eascasas.myhome.cx/1aa0aa2aa8aa7aa0aa5/The-Inside-Out-Revolution-The-Only-Thing-You-Need-to-Know-to-Change-Your-Life-Forever-by-Michael-Neill.pdf
    • http://eascasas.myhome.cx/5aa5aa7aa0aa4aa9/Racine-by-Geoffrey-Brereton.pdf
    • http://eascasas.myhome.cx/5aa5aa7aa0aa5aa3/Racine-Phedre-by-J-P-Short.pdf
    • http://eascasas.myhome.cx/1aa1aa1aa2aa7aa2/Atlas-of-the-Transatlantic-Slave-Trade-by-David-Eltis.pdf
    • http://eascasas.myhome.cx/6aa2aa6aa5aa4aa2/Rizal-Life-Works-And-Ideals-by-Francisco-M-Zul