Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee39a3ae6d3cb8c1…

MALICIOUS

PDF

19.5 KB Created: 2020-02-11 23:03:26 +00:00 Authoring application: mPDF 5.7
MD5: c933f7912853b0412e19ab7b91cf369b SHA-1: fda83576d84e669ccc731e4fb42679c2f77f2b7b SHA-256: ee39a3ae6d3cb8c126bc3dbfbbbe36087e8500290fbb3f4437db21b8db62f9ea
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, hosted on the suspicious domain 'laoieoa.myhome.cx'. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic to malicious or low-quality content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/5c05c02c06c07c00/Brothers-Karamazov-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/1c00c08c03c03c01c06/The-Brothers-Karamazov-MP3-CD-Edition-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/8c01c07c01c09c02/The-Brothers-Karamazov-Annotated-with-short-biography-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/6c00c09c06c09c00/The-Brothers-Karamazov-Backgrounds-and-Sources-Essays-in-Criticism-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/1c00c04c07c08c04c08/The-Brothers-Karamazov-Annotated-with-Critical-Essay-and-Biography-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/9c01c01c04c01c04/The-Brothers-Karamazov-Centaurs-Classics-The-100-greatest-novels-of-all-time---8-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/7c04c03c03c05c00/The-Brother-Karamazov-The-Idiot-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/7c06c04c08c09c01/The-Expanded-Fyodor-Dostoyevsky-Collection-14-Complete-Works-Formatted-for-the-Kindle-Including-linked-Table-of-Contents-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/5c09c03c04c00c05/Crime-and-Punishment-By-Fyodor-Dostoyevsky-amp-Illustrated-An-Audiobook-Free-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/5c08c08c01c01c09/The-Idiot-By-Fyodor-Dostoyevsky---Illustrated-And-Unabridged-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/2c08c06c02c06c08/Great-Short-Works-of-Fyodor-Dostoevsky-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/4c03c01c06c09c01/The-Best-Stories-of-Fyodor-Dostoevsky-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/7c04c03c02c03c07/Fyodor-Dostoevsky-Collection-of-30-Classic-Works-with-analysis-and-historical-background-Annotated-and-Illustrated-Annotated-Classics-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/7c05c07c03c04c04/The-Idiot-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/6c06c08c02c06c07/The-Idiot-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/4c08c02c03c01c08/The-Possessed-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/7c08c07c03c00c01/O-Idiota-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/1c03c05c05c05c04/The-Idiot-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/5c02c04c05c07c03/The-Idiot-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/4c07c00c07c07c09/The-Possessed-by-Fyodor-Dostoyevsky.pdf
    • http://laoieoa.myhome.cx/7c04c03c03c05c0