Malicious PDF — malware analysis report

Static analysis result for SHA-256 de42347f1d77b317…

MALICIOUS

PDF

17.4 KB Created: 2020-03-05 10:54:45 +00:00 Authoring application: mPDF 5.7
MD5: 24238883479ffe868e2baf2674c36b8e SHA-1: 99d36aa04399a211e84a2b735fbc2ed11a8565d7 SHA-256: de42347f1d77b317233e1dc0bdd5519754598adb85b2d2ff126282f2618681cd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to external PDF files hosted on the same domain, suggesting a link farm or a method to distribute malicious content. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tanceubio.myhome.cx/93d63d03d13d13d9/Doctor-Who-City-of-Spires-by-Simon-Bovey.pdf
    • http://tanceubio.myhome.cx/33d23d73d73d03d6/Doctor-Who-Short-Trips-How-the-Doctor-Changed-My-Life-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/53d53d03d33d83d8/Doctor-Who-Shadow-of-Death-Destiny-of-the-Doctor-2-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/13d03d23d53d53d03d0/Creativity-and-the-City-How-the-Creative-Economy-Changes-the-City-by-Simon-Franke.pdf
    • http://tanceubio.myhome.cx/83d33d33d53d93d8/Doctor-Who-The-Day-of-the-Troll-by-Simon-Messingham.pdf
    • http://tanceubio.myhome.cx/53d53d03d43d03d1/Doctor-Who-The-Memory-Cheats-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/83d93d03d83d13d0/Doctor-Who-The-Death-of-Art-by-Simon-Bucher-Jones.pdf
    • http://tanceubio.myhome.cx/53d53d03d33d93d9/Doctor-Who-The-Perpetual-Bond-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/33d93d33d13d93d4/Doctor-Who-The-Empty-House-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/53d53d03d33d93d1/Doctor-Who-The-Judgement-of-Isskar-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/53d53d03d43d03d5/Doctor-Who-The-Cold-Equations-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/53d53d03d33d23d3/The-Scientific-Secrets-of-Doctor-Who-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/53d53d03d53d03d3/Doctor-Who-The-Black-Hole-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/53d53d03d33d93d8/Doctor-Who-The-Guardian-of-the-Solar-System-by-Simon-Guerrier.pdf
    • http://tanceubio.myhome.cx/33d93d43d03d2/The-Mortal-Instruments-the-Complete-Collection-City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-City-of-Heavenly-Fire-by-Cassandra-Clare.pdf
    • http://tanceubio.myhome.cx/33d93d23d13d33d1/Doctor-Who-and-the-City-of-Death-by-David-Lawrence.pdf
    • http://tanceubio.myhome.cx/63d73d83d93d13d7/Blood-on-the-Borders-The-Casebook-of-Dr-Simon-Forman-Elizabethan-Doctor-and-Solver-of-Mysteries-by-Judith-Cook.pdf
    • http://tanceubio.myhome.cx/23d03d53d63d83d9/Hex-and-the-City-Nightside-4-by-Simon-R-Green.pdf
    • http://tanceubio.myhome.cx/43d83d33d43d63d1/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://tanceubio.myhome.cx/13d53d73d03d53d1/City-of-the-Iron-Fish-by-Simon-Ings.pdf
    • http://tanceubio.myhome.cx/53d53d03d43d03d5/Doctor-Who-The-Cold-Equations-by-