Malicious PDF — malware analysis report

Static analysis result for SHA-256 04a3a53df08f091d…

MALICIOUS

PDF

23.6 KB Created: 2019-05-01 17:25:55 +01:00 Authoring application: mPDF 5.7
MD5: 557829b00c66f5330c63b5795bb0e7da SHA-1: 3b61293a2928b48d61071ea0c03f7d2ffab2e86c SHA-256: 04a3a53df08f091db57f4220e256b36e0171274cca6c47eda0e5799d06cca6aa
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection to malicious content. While the document body is heavily corrupted, the presence of numerous external links points towards a phishing or malware distribution attempt. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7203205206203206/La-Chauve-Souris-Et-Le-Papillon-Correspondance-Montesquiou-Whistler-by-Joy-Newton.pdf
    • http://xiixmcuin.linkpc.net/7203205206203201/Le-myst-re-de-la-chauve-souris-by-Gustave-Toudouze.pdf
    • http://xiixmcuin.linkpc.net/7203205205202206/La-fille-de-la-chauve-souris-M-moires-by-Nana-Mouskouri.pdf
    • http://xiixmcuin.linkpc.net/7203205206206203/Balieff-s-Chauve-souris-of-Moscow-American-season-under-the-direction-of-F-Ray-Comstock-and-Morris-Gest-by-Teatr-_Letuchaia-mysh-39-_.pdf
    • http://xiixmcuin.linkpc.net/6209205206203205/Papillon-May-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206204206/Papillon-December-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206203206/Papillon-February-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206204205/Papillon-March-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206203209/Papillon-April-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206204200/Papillon-January-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/7207205206208204/Correspondance-by-Voltaire.pdf
    • http://xiixmcuin.linkpc.net/7203204207201207/Newton-s-Principia-by-Isaac-Newton.pdf
    • http://xiixmcuin.linkpc.net/8206205201204208/Newton-s-Principia-Newton-s-Principia-The-Mathematical-Principles-of-Natural-Philosophy-1846-the-Mathematical-Principles-of-Natural-Philosophy-184-by-Isaac-Newton.pdf
    • http://xiixmcuin.linkpc.net/6205205201202200/Pierre-Bouguer-1698-1758-Un-Blaise-Pascal-Du-Xviiie-Siecle-Suivi-D-Une-Correspondance-by-Roland-Lamontagne.pdf
    • http://xiixmcuin.linkpc.net/5204205203208205/Ionesco-La-Cantatrice-Chauve-and-Les-Chaises-by-Glenn-S-Holland.pdf
    • http://xiixmcuin.linkpc.net/3204209208202203/To-Die-for-the-People-The-Writings-of-Huey-P-Newton-by-Huey-P-Newton.pdf
    • http://xiixmcuin.linkpc.net/3202209206206208/Torn-by-Sage-Whistler.pdf
    • http://xiixmcuin.linkpc.net/1201206201202203/Mister-Whistler-by-Margaret-Mahy.pdf
    • http://xiixmcuin.linkpc.net/5209202203201207/The-Suicide-Octave-by-Mike-Whistler.pdf
    • http://xiixmcuin.linkpc.net/7201201204206201/-nigme-au-Grand-Stade-Souris-noire-by-Danielle-Thi-ry.pdf