Malicious PDF — malware analysis report

Static analysis result for SHA-256 fb3174d54b518d79…

MALICIOUS

PDF

18.8 KB Created: 2020-03-20 07:41:29 +00:00 Authoring application: mPDF 5.7
MD5: ddd05163ddde234aca50d9f476a9f82f SHA-1: 6fe87887adaace65e783b563b6b32ed2fbc3f7fb SHA-256: fb3174d54b518d792f291dcea8e2b93ed8f4f6c51bdc32ce68101cc4d4e6fa9d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'laoieoa.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laoieoa.myhome.cx/2c06c07c08c00c03/Thoreau-Walden-and-Other-Writings-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/7c05c00c05c09c01/Walden-By-Henry-David-Thoreau---Illustrated-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/1c00c02c01c08c00/Walden-and-Other-Writings-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/6c00c05c01c06c04/Walden-ou-La-Vie-dans-les-bois-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/5c06c00c00c03c06/Walden-Or-Life-in-the-Woods-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/1c01c07c07c09c02c08/Walden-and-Civil-Disobedience-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/8c01c05c09c00c02/Walden-Ou-la-vie-dans-les-bois-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/5c09c09c06c06c09/Walden-and-Civil-Disobedience-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/6c00c01c06c02c05/Walden---Essay-on-Civil-Disobedience-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/8c00c03c00c01c03/Walden-Color-Illustrated-Formatted-for-E-Readers-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/5c07c09c08c06c04/Walden-Black-Illustrated-Classics-Bonus-Free-Audiobook-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/4c03c06c05c05c00/A-Week-on-the-Concord-and-Merrimack-Rivers-Walden-The-Maine-Woods-Cape-Cod-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/8c09c05c05c04c02/Walden-oder-Leben-in-den-W-ldern-Vollst-ndig-berarbeitete-deutsche-Ausgabe-mit-neuer-Rechtschreibung-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/5c09c00c03c06c08/Walden-ou-La-Vie-dans-les-Bois-Annot--Version-Francaise-Version-Originale-en-Anglais-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/2c05c02c03c01c08/The-Price-of-Freedom-Political-Philosophy-from-Thoreau-s-Journals-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/8c05c01c08c07c00/Thumbing-Through-Thoreau-A-Book-of-Quotations-by-Henry-David-Thoreau-by-Kenny-Luck.pdf
    • http://laoieoa.myhome.cx/8c05c01c08c06c05/Uncommon-Learning-Thoreau-on-Education-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/8c05c01c09c09c07/Material-Faith-Thoreau-on-Science-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/3c09c01c04c04c01/The-Heart-of-Thoreau-s-Journals-by-Henry-David-Thoreau.pdf
    • http://laoieoa.myhome.cx/8c05c01c09c08c04/Thoreau-Political-Writings-by-Henry-David-Thoreau.pdf