Malicious PDF — malware analysis report

Static analysis result for SHA-256 0523d707c75d1231…

MALICIOUS

PDF

16.4 KB Created: 2019-05-01 20:14:59 +01:00 Authoring application: mPDF 5.7
MD5: 106421564730a6bad6b2cfa5ac78c4c1 SHA-1: 5f80f3be556e76b037e5b71098f0cbe735948404 SHA-256: 0523d707c75d12315400758cb5d1b9b175a232ef515f9b4edb6197045c1e7e27
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. The ML classifier also flagged the document as malicious. The primary attack pattern involves directing users to a collection of external PDFs, likely for SEO manipulation or to host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5209202207203200/Knock-Knock-Who-s-There-by-James-Hadley-Chase.pdf
    • http://xiixmcuin.linkpc.net/5209202208205201/Knock-Knock-Jokes-for-Kids-301-Hilarious-and-Funny-Knock-Knock-Jokes-by-Lizzy-Burbank.pdf
    • http://xiixmcuin.linkpc.net/5209202208204207/Knock-Knock-Jokes-for-Kids-50-Funny-Knock-Knock-Jokes-for-Kids-Funny-and-Hilarious-Joke-Books-for-Children-by-Johnny-B-Laughing.pdf
    • http://xiixmcuin.linkpc.net/2203208207207208/A-Foldout-History-of-Antidepressants-A-Timeline-for-Amateurs-and-Aficionados-by-Knock-Knock.pdf
    • http://xiixmcuin.linkpc.net/4208202209203209/Boo-Who-And-Other-Wicked-Halloween-Knock-Knock-Jokes-by-Katy-Hall.pdf
    • http://xiixmcuin.linkpc.net/1203200200207207/Knock-Knock-Psychic-Visions-5-by-Dale-Mayer.pdf
    • http://xiixmcuin.linkpc.net/5209202208208200/101-Knock-Knock-Jokes-for-Kids-by-Arnie-Lightning.pdf
    • http://xiixmcuin.linkpc.net/5209202207206204/Knock-Knock-by-Anna-Clara-Tidholm.pdf
    • http://xiixmcuin.linkpc.net/5209202208209202/Cliches-amp-Platitudes-For-All-Occasions-by-Knock-Knock.pdf
    • http://xiixmcuin.linkpc.net/5209202208208204/Camp-Knock-Knock-by-Betsy-Duffey.pdf
    • http://xiixmcuin.linkpc.net/9209200203/Knock-Knock-My-Dad-s-Dream-for-Me-by-Daniel-Beaty.pdf
    • http://xiixmcuin.linkpc.net/5209202208205200/Knock-Knock-by-Kaori-Takahashi.pdf
    • http://xiixmcuin.linkpc.net/5209202208204208/Knock-Knock-by-Jules-Feiffer.pdf
    • http://xiixmcuin.linkpc.net/3204203205205209/Knock-Knock-You-re-Dead-A-Hamish-Macbeth-Short-Story-Hamish-Macbeth-30-5-by-M-C-Beaton.pdf
    • http://xiixmcuin.linkpc.net/7206200204204203/Have-This-One-on-Me-by-James-Hadley-Chase.pdf
    • http://xiixmcuin.linkpc.net/8209207204204/Mallory-by-James-Hadley-Chase.pdf
    • http://xiixmcuin.linkpc.net/8208202204203/An-Ace-Up-My-Sleeve-by-James-Hadley-Chase.pdf
    • http://xiixmcuin.linkpc.net/8205205205208/You-Find-Him-I-ll-Fix-Him-by-James-Hadley-Chase.pdf
    • http://xiixmcuin.linkpc.net/1208200209203201/You-ve-Got-It-Coming-by-James-Hadley-Chase.pdf
    • http://xiixmcuin.linkpc.net/8206204200208/Well-Now-My-Pretty-by-James-Hadley-Chase.pdf