Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0b34da289df4e9d…

MALICIOUS

PDF

18.1 KB Created: 2020-02-05 08:58:33 +00:00 Authoring application: mPDF 5.7 First seen: 2020-12-28
MD5: 456e9f95af75f10ddf81f7cd7ae99565 SHA-1: 5258883a532df9778bfb67568016fff5f8523c47 SHA-256: c0b34da289df4e9dc3c6b1505131e212efa9ca8d32993a7f7eb8ee4e4f078179
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a suspicious domain hosting numerous files, likely as a lure or to distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/5c09c00c03c06c02/Crime-et-Ch-timent-Version-fran-aise-by-Fyodor-Dostoyevsky.pdf In PDF document text
    • http://laoieoa.myhome.cx/5c09c03c04c00c05/Crime-and-Punishment-By-Fyodor-Dostoyevsky-amp-Illustrated-An-Audiobook-Free-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/8c00c03c02c02c08/Delusions-of-a-Man-Baisse-Delusions-of-a-Declining-Man-Version-Fran-aise-by-Robert-Logsdon.pdfIn PDF document text
    • http://laoieoa.myhome.cx/9c00c05c01c04c02/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/7c01c00c09c02c05/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/3c01c07c02c09c03/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c03c00c06c02/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/8c03c01c04c05/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/1c00c08c03c01c08c03/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/1c01c01c05c09c06c04/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/7c01c03c03c06c05/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c05c09c08c09c04/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/8c09c01c08c03c00/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c07c04c09c08c01/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/3c07c00c05c08c09/Crime-and-Punishment-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/6c02c04c09c05c03/Crime-and-Punishment-Annotated-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/7c06c04c08c09c01/The-Expanded-Fyodor-Dostoyevsky-Collection-14-Complete-Works-Formatted-for-the-Kindle-Including-linked-Table-of-Contents-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c08c03c03c08c01/Crime-and-Punishment-Pilgrim-Classics-Annotated-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/5c03c01c07c03c05/Crime-and-Punishment---The-Greatest-Masterpieces-of-Russian-Literature-by-Fyodor-Dostoyevsky.pdfIn PDF document text
    • http://laoieoa.myhome.cx/1c01c00c06c02c06c01/Crime-and-Punishment-The-Modern-Library-of-the-World-s-Best-Books-by-Fyodor-Dostoyevsky.pdfIn PDF document text