Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb8f3218e9485782…

MALICIOUS

PDF

18.7 KB Created: 2020-03-14 00:25:08 +00:00 Authoring application: mPDF 5.7
MD5: 737f6a5d2ddd60605353673f0b193705 SHA-1: 8f36047414871d79ef7cab35faea912a31fea8a4 SHA-256: cb8f3218e9485782ccb1e5bb63546c6157cea907cd04cb5e1dcf71bc21c4933d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. These URLs point to external PDF files, suggesting a link farm or a distribution mechanism for further malicious content. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9775

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tikytsesapdf.myhome.cx/878c778c178c978c278c4/Cat-on-a-Hot-Tin-Roof-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/178c078c078c978c178c0/Not-About-Nightingales-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/378c778c678c578c878c0/The-Dark-Room-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/478c778c478c378c778c0/Spring-Storm-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/378c278c578c278c5/The-Glass-Menagerie-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/878c878c378c778c478c2/The-Glass-Menagerie-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/478c078c878c278c878c2/The-Night-of-the-Iguana-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/278c978c578c878c378c7/Baby-Doll-and-Other-Plays-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/278c078c978c778c978c9/Sweet-Bird-of-Youth-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/378c178c578c078c278c0/A-Streetcar-Named-Desire-by-Tennessee-Williams.pdf
    • http://tikytsesapdf.myhome.cx/978c678c678c678c5/Follies-of-God-Tennessee-Williams-and-the-Women-of-the-Fog-by-James-Grissom.pdf
    • http://tikytsesapdf.myhome.cx/778c378c078c578c278c0/Walking-on-Glass-A-Memoir-of-the-Later-Days-of-Tennessee-Williams-by-Scott-Kenan.pdf
    • http://tikytsesapdf.myhome.cx/178c078c778c278c478c478c7/-quot-Forever-Young-quot-Nach-Tennessee-Williams-quot-S-sser-Vogel-Jugend-Sweet-Bird-Of-Youth-quot-Eine-Bearbeitung-Von-Frank-Castorf-by-Carl-Hegemann.pdf
    • http://tikytsesapdf.myhome.cx/578c978c978c378c8/The-Nightingale-Scripts-by-Jason-Nightingale.pdf
    • http://tikytsesapdf.myhome.cx/278c378c878c478c178c2/Eating-for-England-The-Delights-and-Eccentricities-of-the-British-at-the-Table-by-Nigel-Slater.pdf
    • http://tikytsesapdf.myhome.cx/278c378c778c878c878c2/Florence-Nightingale---To-Her-Nurses-by-Florence-Nightingale.pdf
    • http://tikytsesapdf.myhome.cx/178c378c678c478c878c3/The-Collected-Poems-of-Williams-Carlos-Williams-1939-1962-by-William-Carlos-Williams.pdf
    • http://tikytsesapdf.myhome.cx/978c478c378c178c778c8/Tennessee-Simply-Beautiful-by-Schatz.pdf
    • http://tikytsesapdf.myhome.cx/878c178c378c678c078c2/Marmaduke-of-Tennessee-by-Edward-Cummings.pdf
    • http://tikytsesapdf.myhome.cx/578c678c278c478c278c3/Elevations-in-Tennessee-by-Elizabeth-Cockrill.pdf