Malicious PDF — malware analysis report

Static analysis result for SHA-256 07b3cb5fe04edc68…

MALICIOUS

PDF

15.9 KB Created: 2019-05-02 17:15:19 +01:00 Authoring application: mPDF 5.7
MD5: 407b5509a9314444a998f84fbc700b89 SHA-1: d4b5dc833655109ccffca0fd20ba1f8802345aec SHA-256: 07b3cb5fe04edc68aec8ff956acbfc4669ef63d60777a62277e647ebc326747e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The URLs are hosted on a dynamic DNS domain, suggesting an attempt to obscure the true hosting location of potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5208206207201201/Happy-Dog-Happy-Human-A-Realization-of-Needs-amp-Wants-by-Matthew-Crans.pdf
    • http://xiixmcuin.linkpc.net/5201205203208205/Happy-Death-Day---Happy-Death-Day-Jisatsu-ya-Yomiji-to-Satsujinki-Dorian-Happy-Death-Day-1-by-.pdf
    • http://xiixmcuin.linkpc.net/2209201206208200/The-Happy-Addict-How-to-be-Happy-in-Recovery-from-Alcoholism-or-Drug-Addiction-by-Beth-Burgess.pdf
    • http://xiixmcuin.linkpc.net/5207206207204209/Happy-for-No-Reason-7-Steps-to-Being-Happy-from-the-Inside-Out-by-Marci-Shimoff.pdf
    • http://xiixmcuin.linkpc.net/3200203207207/Finding-Happy-Happy-Montana-1-by-Zanne-Sweeney.pdf
    • http://xiixmcuin.linkpc.net/4201201207206200/This-Is-What-Happy-Looks-Like-This-Is-What-Happy-Looks-Like-1-by-Jennifer-E-Smith.pdf
    • http://xiixmcuin.linkpc.net/7201202201207209/Naoki-Urasawa-pr-sente-Happy-Volume-1-Are-You-Happy-Happy-1-by-Naoki-Urasawa.pdf
    • http://xiixmcuin.linkpc.net/4206207201200204/The-Happy-Hollisters-at-Mystery-Mountain-Happy-Hollisters-5-by-Jerry-West.pdf
    • http://xiixmcuin.linkpc.net/4206207201201203/The-Happy-Hollisters-and-the-Cowboy-Mystery-Happy-Hollisters-20-by-Jerry-West.pdf
    • http://xiixmcuin.linkpc.net/1202207202202207/Happy-Bay-by-Tim-Stelma.pdf
    • http://xiixmcuin.linkpc.net/1206202207205200/Mostly-Happy-by-Pam-Bustin.pdf
    • http://xiixmcuin.linkpc.net/4208201209202204/Ask-Me-if-I-m-Happy-by-Kimberly-Menozzi.pdf
    • http://xiixmcuin.linkpc.net/9201206208204201/Too-Happy-by-Kate-Kasten.pdf
    • http://xiixmcuin.linkpc.net/1203209202205201/Something-Like-Happy-by-John-Burnside.pdf
    • http://xiixmcuin.linkpc.net/4205204203206205/Wake-Up-Happy-Every-Day-by-Stephen-May.pdf
    • http://xiixmcuin.linkpc.net/2209201203204201/Happy-Ending-by-David-Rat.pdf
    • http://xiixmcuin.linkpc.net/8206205207209202/I-m-So-Happy-for-You-by-Lucinda-Rosenfeld.pdf
    • http://xiixmcuin.linkpc.net/1201201205202203/More-Happy-Than-Not-by-Adam-Silvera.pdf
    • http://xiixmcuin.linkpc.net/2202204/After-Ever-Happy-After-4-by-Anna-Todd.pdf
    • http://xiixmcuin.linkpc.net/2202208205202204/Happy-Ever-After-by-Patricia-Scanlan.pdf