Malicious PDF — malware analysis report

Static analysis result for SHA-256 c211e052e2767c4a…

MALICIOUS

PDF

26.3 KB Created: 2020-03-18 16:30:50 +00:00 Authoring application: mPDF 5.7
MD5: 4e33528d24d0d11f5f54a61b5cce7990 SHA-1: 943daaa194b72bfe3bf2cb1d1847016cdd31ff21 SHA-256: c211e052e2767c4a80694b877e4f0dcb68e00dbe4bd41dd011c1369e227a51e5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, forming a link farm. These links, such as http://rtuninnsi.myhome.cx/76a36a66a06a86a1/The-Escape-Artists-A-Band-of-Daredevil-Pilots-and-the-Greatest-Prison-Break-of-the-Great-War-by-Neal-Bascomb.pdf, likely serve to redirect users to malicious websites or download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rtuninnsi.myhome.cx/76a36a66a06a86a1/The-Escape-Artists-A-Band-of-Daredevil-Pilots-and-the-Greatest-Prison-Break-of-the-Great-War-by-Neal-Bascomb.pdf
    • http://rtuninnsi.myhome.cx/46a36a26a46a76a2/The-Escape-Artists-A-Band-of-Daredevil-Pilots-and-the-Greatest-Prison-Break-of-the-Great-War-by-Neal-Bascomb.pdf
    • http://rtuninnsi.myhome.cx/36a06a96a46a56a9/Escape-From-Davao-The-Forgotten-Story-of-the-Most-Daring-Prison-Break-of-the-Pacific-War-by-John-D-Lukacs.pdf
    • http://rtuninnsi.myhome.cx/46a06a96a26a56a1/The-Great-Escape-from-Stalag-Luft-III-The-Full-Story-of-How-76-Allied-Officers-Carried-Out-World-War-II-s-Most-Remarkable-Mass-Escape-by-Tim-Carroll.pdf
    • http://rtuninnsi.myhome.cx/46a46a26a46a16a8/Captured-by-a-Scoundrel-Regency-Prison-Break-2-by-Sharon-Page.pdf
    • http://rtuninnsi.myhome.cx/16a16a96a16a6/Killing-Fear-Prison-Break-Trilogy-1-by-Allison-Brennan.pdf
    • http://rtuninnsi.myhome.cx/76a96a56a66a96a3/Great-Composers-Great-Artists-Portraits-by-Stewart-Buettner.pdf
    • http://rtuninnsi.myhome.cx/36a66a36a66a26a1/Escape-from-the-Prison-System-Finding-the-Narrow-Door-by-Pat-W-Kirk.pdf
    • http://rtuninnsi.myhome.cx/16a96a66a86a46a4/No-Wall-Too-High-One-Man-s-Daring-Escape-from-Mao-s-Darkest-Prison-by-Xu-Hongci.pdf
    • http://rtuninnsi.myhome.cx/26a56a66a76a66a7/Give-Me-a-Break-How-I-Exposed-Hucksters-Cheats-and-Scam-Artists-and-Became-the-Scourge-of-the-Liberal-Media-by-John-Stossel.pdf
    • http://rtuninnsi.myhome.cx/76a26a96a06a9/First-Break-All-the-Rules-What-the-World-s-Greatest-Managers-Do-Differently-by-Marcus-Buckingham.pdf
    • http://rtuninnsi.myhome.cx/46a96a26a66a06a6/The-Daily-Entrepreneur-33-Success-Habits-for-Small-Business-Owners-Freelancers-and-Aspiring-9-to-5-Escape-Artists-by-S-J-Scott.pdf
    • http://rtuninnsi.myhome.cx/16a96a46a16a66a7/Hero-Found-The-Greatest-POW-Escape-of-the-Vietnam-War-by-Bruce-Henderson.pdf
    • http://rtuninnsi.myhome.cx/86a66a06a36a36a5/Houdini-World-s-Greatest-Mystery-Man-and-Escape-King-by-Kathleen-Krull.pdf
    • http://rtuninnsi.myhome.cx/46a26a66a86a26a4/Wrong-Side-of-the-Wall-The-Life-of-Blackie-Schwamb-the-Greatest-Prison-Baseball-Player-of-All-Time-by-Eric-Stone.pdf
    • http://rtuninnsi.myhome.cx/26a96a16a86a1/Shot-All-to-Hell-Jesse-James-the-Northfield-Raid-and-the-Wild-West-s-Greatest-Escape-by-Mark-Lee-Gardner.pdf
    • http://rtuninnsi.myhome.cx/16a16a06a26a06a86a7/Set-Yourself-Free-Reon-Schutte-s-10-Principles-to-Break-Out-of-Your-Personal-Prison-Through-the-Power-of-Choice-by-Reon-Schutte.pdf
    • http://rtuninnsi.myhome.cx/46a46a86a06a36a6/The-Great-Escape-By-Any-Other-Name-1-5-by-Tia-Fielding.pdf
    • http://rtuninnsi.myhome.cx/46a96a76a56a76a7/Grown-Up-All-Wrong-75-Great-Rock-and-Pop-Artists-from-Vaudeville-to-Techno-by-Robert-Christgau.pdf
    • http://rtuninnsi.myhome.cx/46a06a36a46a46a6/The-Great-Escape-by-Paul-Brickhill.pdf
    • http://rtuninnsi.myhome.cx/46a06a96a26a56a1/The-Great-Escape-from-Stalag-Luft-III-The-Full-Story-of-How-76-Allied-Officers-Carri