Malicious PDF — malware analysis report

Static analysis result for SHA-256 c160d8f5a98fec71…

MALICIOUS

PDF

17.4 KB Created: 2020-03-12 03:06:15 +00:00 Authoring application: mPDF 5.7
MD5: 15a4d5263210af96c6ccab8f64e00245 SHA-1: 0b92c4b73db4837dd7f69e6cb04b43b630a79e31 SHA-256: c160d8f5a98fec71fef66551b942315005f03df8972839f203c3147f5ef3998b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to the same domain, indicating a link farm designed to redirect users. The ML classifier strongly flagged this PDF as malicious, and the PDF_SEO_LINK_FARM heuristic confirms the suspicious link distribution. The primary purpose appears to be to host numerous links that likely lead to malicious downloads or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/4558555550551557/Christmas-with-Hope-Wounded-Heroes-Series-Prequel-by-Anne-Patrick.pdf
    • http://ieuicufioao.myhome.cx/1557554555556553/Ellie-s-Wounded-Heroes-Wounded-Warriors-1-by-Marla-Monroe.pdf
    • http://ieuicufioao.myhome.cx/3558558559550550/The-Wounded-Shadow-The-Darkwater-Saga-3-by-Patrick-W-Carr.pdf
    • http://ieuicufioao.myhome.cx/7552551550551/The-Wounded-Heart-Hope-for-Adult-Victims-of-Childhood-Sexual-Abuse-by-Dan-B-Allender.pdf
    • http://ieuicufioao.myhome.cx/4559552557558557/The-Wounded-Heart-Hope-for-Adult-Victims-of-Childhood-Sexual-Abuse-by-Dan-B-Allender.pdf
    • http://ieuicufioao.myhome.cx/5550552556550558/The-Wounded-Buzzard-on-Christmas-Eve-Hank-the-Cowdog-13-by-John-R-Erickson.pdf
    • http://ieuicufioao.myhome.cx/5550553553552550/A-Blue-and-Gray-Christmas-Christmas-Keeps-Love-and-Hope-Alive-During-War-by-Vickie-McDonough.pdf
    • http://ieuicufioao.myhome.cx/2557550551552552/The-Christmas-Blessing-Christmas-Hope-2-by-Donna-VanLiere.pdf
    • http://ieuicufioao.myhome.cx/2557551557554554/The-Christmas-Light-Christmas-Hope-7-by-Donna-VanLiere.pdf
    • http://ieuicufioao.myhome.cx/4554556551559552/Angels-All-Around-Threshold-Series-Prequel-by-Christa-Kinde.pdf
    • http://ieuicufioao.myhome.cx/6558553558557551/Alias-Shadowed-Prequel-Series-12-by-Lizzie-Skurnick.pdf
    • http://ieuicufioao.myhome.cx/6558553559550555/Alias-Skin-Deep-Prequel-Series-11-by-Catherine-Hapka.pdf
    • http://ieuicufioao.myhome.cx/1555559556557558/Andromeda-s-Fall-The-Prequel-Legion-Series-1-by-William-C-Dietz.pdf
    • http://ieuicufioao.myhome.cx/6558553558559556/Alias-Free-Fall-Prequel-Series-8-by-Christa-Roberts.pdf
    • http://ieuicufioao.myhome.cx/3554550553550555/Star-Wars-Heroes-for-a-New-Hope-by-Mark-Waid.pdf
    • http://ieuicufioao.myhome.cx/1554553552559557/A-Christmas-Grace-Christmas-Stories-6-by-Anne-Perry.pdf
    • http://ieuicufioao.myhome.cx/3557553550556550/A-Christmas-Journey-Christmas-Stories-1-by-Anne-Perry.pdf
    • http://ieuicufioao.myhome.cx/3555558559554555/A-Christmas-Journey-Christmas-Stories-1-by-Anne-Perry.pdf
    • http://ieuicufioao.myhome.cx/1554553558551555/A-Christmas-Journey-Christmas-Stories-1-by-Anne-Perry.pdf
    • http://ieuicufioao.myhome.cx/3552550558552557/A-Christmas-Promise-Christmas-Stories-7-by-Anne-Perry.pdf
    • http://ieuicufioao.myhome.cx/5550553553552550/A-Blue-and-Gray-Christmas-Christmas-Keeps-Love-and-Hope-Alive-Dur