Malicious PDF — malware analysis report

Static analysis result for SHA-256 c36f95eec6cf6fa0…

MALICIOUS

PDF

16.5 KB Created: 2020-03-12 02:12:36 +00:00 Authoring application: mPDF 5.7 First seen: 2021-06-28
MD5: 5ba8f301ad51dd692d272a4c65c0848b SHA-1: bc51ccac2812cc594955d258aea3e17807fc6fac SHA-256: c36f95eec6cf6fa09df17efc0f93a5dc584437aab9ed1cec0f8899e990e012f2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, all pointing to the same domain. This suggests a link farm or redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/2554557557551/Clarkesworld-Magazine-Issue-71-Clarkesworld-Magazine-71-by-Neil-Clarke.pdf In PDF document text
    • http://ieuicufioao.myhome.cx/2554558551555/Clarkesworld-Magazine-Issue-80-Clarkesworld-Magazine-80-by-Neil-Clarke.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2552553557558559/Clarkesworld-Magazine-Issue-62-Clarkesworld-Magazine-62-by-Neil-Clarke.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1550555559555551558/Clarkesworld-Magazine-Issue-86-Clarkesworld-Magazine-86-by-Neil-Clarke.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2556550552558/Clarkesworld-Magazine-Issue-76-Clarkesworld-Magazine-76-by-Neil-Clarke.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2554558550550/Clarkesworld-Magazine-Issue-37-Clarkesworld-Magazine-37-by-Neil-Clarke.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2557554552555557/Realms-The-First-Year-of-Clarkesworld-Magazine-by-Nick-Mamatas.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1551554553553553550/Sacred-Hoop-Magazine-Issue-82-Sacred-Hoop-Magazine-e-book-text-only-version-Issue-82-by-Ken-Hyder.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/4550558552555554/Massacre-Magazine-Issue-4-by-Julia-Kavan.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1550553551551559557/Divergent-Magazine-Issue-2-by-Jack-Crowder.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/4550558552553559/Massacre-Magazine-Issue-5-by-Julia-Kavan.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/4550558552556555/Massacre-Magazine-Issue-3-by-Julia-Kavan.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/4557551558558559/Apex-Magazine-Issue-59-by-Sigrid-Ellis.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2554554553555/Apex-Magazine-Issue-80-by-Jason-Sizemore.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/6557556556551559/Phobos-Magazine-Issue-One-Zugzwang-by-A-E-Decker.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/1550552550552557554/Feverish-Fiction-Magazine-issue-3-by-Michael-Faun.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/7551550558551555/Photoworks-biannual-magazine-Issue-13-by-K-ichi-Kuroda.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/5556554559552559/Faerie-Magazine-Issue-27-Summer-2014-by-Carolyn-Turgeon.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/2555559557551/Uncanny-Magazine-Issue-18-September-October-2017-by-Lynne-M-Thomas.pdfIn PDF document text
    • http://ieuicufioao.myhome.cx/8555556552555/The-Journal-CEO-Magazine-A-Personal-Journaling-Magazine-by-The-Journal-CEO-Magazine.pdfIn PDF document text