Malicious PDF — malware analysis report

Static analysis result for SHA-256 f31f4e49841c8523…

MALICIOUS

PDF

16.0 KB Created: 2020-03-18 22:14:49 +00:00 Authoring application: mPDF 5.7
MD5: f68b04264af6e07c02c6368091a55e2c SHA-1: 69cf5ba0a1a6b00f82b3e6765b2f1d2481e67dce SHA-256: f31f4e49841c852332cd82ca97cf601ac3c0430b46f85244cd4b1922b0f9dba0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute malware. The ML classifier strongly supports a malicious verdict. The primary attack pattern involves directing users to a link farm hosted on 'ieuicufioao.myhome.cx'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/8554559555559555/Growing-Pelargoniums-and-Geraniums-A-Complete-Guide-by-Beryl-Stockton.pdf
    • http://ieuicufioao.myhome.cx/8554559555552552/A-Persistence-of-Geraniums-by-John-Linwood-Grant.pdf
    • http://ieuicufioao.myhome.cx/8554559555552554/The-Red-Geraniums-by-J-Schlenker.pdf
    • http://ieuicufioao.myhome.cx/8554559554554558/Hardy-Geraniums-by-Peter-Yeo.pdf
    • http://ieuicufioao.myhome.cx/8554559555558555/My-Little-White-Geraniums-by-Brandon-Berntson.pdf
    • http://ieuicufioao.myhome.cx/8554559555559553/Geraniums-Lilacs-and-Rosebuds-by-Antoinette-Harvey.pdf
    • http://ieuicufioao.myhome.cx/8554559554555552/He-Kissed-Me-Between-the-Geraniums-and-the-Daisies-by-Janice-Silkworth.pdf
    • http://ieuicufioao.myhome.cx/8554559554555557/Surprised-Pink-Geraniums-A-Memoir-by-Pat-Brown.pdf
    • http://ieuicufioao.myhome.cx/8554559553554552/Hardy-Geraniums-Wisley-Handbooks-by-David-Hibberd.pdf
    • http://ieuicufioao.myhome.cx/8554559554555558/Cabbages-and-Geraniums-Memories-of-the-Holocaust-by-Valerie-Furth.pdf
    • http://ieuicufioao.myhome.cx/1551551552554550554/Tod-im-Kilt-John-Mackenzies-zweiter-Fall-John-Mackenzie-2-by-Emma-Goodwyn.pdf
    • http://ieuicufioao.myhome.cx/1550550557554554/John-s-Secret-Dreams-The-Life-of-John-Lennon-by-Doreen-Rappaport.pdf
    • http://ieuicufioao.myhome.cx/3557550555555557/Unfit-For-Command-Swift-Boat-Veterans-Speak-Out-Against-John-Kerry-by-John-E-O-39-Neill.pdf
    • http://ieuicufioao.myhome.cx/1551554552559559/Cairngorm-John-A-Life-in-Mountain-Rescue-by-John-Allen.pdf
    • http://ieuicufioao.myhome.cx/1551550552557550550/John-Skelton-the-Complete-English-Poems-by-John-Scattergood.pdf
    • http://ieuicufioao.myhome.cx/5557551559552553/The-Educational-Philosophy-Of-St-John-Bosco-by-John-A-Morrison.pdf
    • http://ieuicufioao.myhome.cx/2553555554555/John-Sloan-Painter-and-Rebel-by-John-Loughery.pdf
    • http://ieuicufioao.myhome.cx/1556557553553558/Discovering-the-Arctic-The-Story-of-John-Rae-by-John-Wilson.pdf
    • http://ieuicufioao.myhome.cx/4557555553552553/Papa-John-An-Autobiography-by-John-Phillips-by-John-Phillips.pdf
    • http://ieuicufioao.myhome.cx/1551551559554550552/John-Burnet-of-Barns-by-John-Buchan.pdf
    • http://ieuicufioao.myhome.cx/1551551552554550554/Tod-im-Kilt-John-Mac