Malicious PDF — malware analysis report

Static analysis result for SHA-256 08b620a9b4f2ba23…

MALICIOUS

PDF

18.2 KB Created: 2019-04-30 04:07:04 +01:00 Authoring application: mPDF 5.7
MD5: 096a9a9bc89db4dc1048e33d758e1dba SHA-1: fcf1502afc331762e3b4fb8d63ee297fb74ab342 SHA-256: 08b620a9b4f2ba232dd78bac360729eff1b90ee64caff25503e345766dda9c9d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a critical heuristic for containing a mass external link farm, with numerous URLs pointing to book-related PDFs. The ML classifier also strongly indicated maliciousness. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest an attempt to manipulate search engine results or distribute content through a link farm, which is a common tactic for SEO spam or potentially distributing malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4209204201203207/Theory-and-Treatment-of-Anorexia-Nervosa-and-Bulimia-Biomedical-Sociocultural-and-Psychological-Perspectives-by-Steven-Emmett.pdf
    • http://xiixmcuin.linkpc.net/4209203208208201/Anorexia-Nervosa-A-Guide-to-Recovery-by-Lindsey-Hall.pdf
    • http://xiixmcuin.linkpc.net/4209204203206203/Anorexia-Nervosa-Finding-the-Life-Line-by-Barbara-C-Unell.pdf
    • http://xiixmcuin.linkpc.net/4209203208206206/Ten-Mile-Morning-My-Journey-Through-Anorexia-Nervosa-by-Adam-Lamparello.pdf
    • http://xiixmcuin.linkpc.net/4209204201204207/Eating-Disorders-Obesity-Anorexia-Nervosa-And-The-Person-Within-by-Hilde-Bruch.pdf
    • http://xiixmcuin.linkpc.net/4209204203205208/The-Thin-Woman-Feminism-Post-Structuralism-and-the-Social-Psychology-of-Anorexia-Nervosa-by-Helen-Malson.pdf
    • http://xiixmcuin.linkpc.net/3205202209204205/The-Luckiest-Girl-in-the-World-by-Steven-Levenkron.pdf
    • http://xiixmcuin.linkpc.net/4201209202209208/Treating-Ty-Veteran-2-by-Bobby-Michaels.pdf
    • http://xiixmcuin.linkpc.net/8208205203203200/Tovi-the-Penguin-Goes-Trick-or-Treating-by-Janina-Rossiter.pdf
    • http://xiixmcuin.linkpc.net/4209203207204201/Empty-A-Story-of-Anorexia-by-Christie-Pettit.pdf
    • http://xiixmcuin.linkpc.net/7200205204201205/Treating-Complex-Trauma-in-Adolescents-and-Young-Adults-by-John-N-Briere.pdf
    • http://xiixmcuin.linkpc.net/4206201206205206/Cultural-Cancer-Treating-the-Disease-of-Political-Correctness-by-Daryl-Kane.pdf
    • http://xiixmcuin.linkpc.net/1208206207209206/Treating-Trauma-and-Traumatic-Grief-in-Children-and-Adolescents-by-Judith-A-Cohen.pdf
    • http://xiixmcuin.linkpc.net/1200203203201207202/Healing-Physician-Burnout-Diagnosing-Preventing-and-Treating-by-Quint-Studer.pdf
    • http://xiixmcuin.linkpc.net/9207201200207207/Treating-Traumatized-Children-Risk-Resilience-and-Recovery-by-Danny-Brom.pdf
    • http://xiixmcuin.linkpc.net/4209204203205209/Starving-A-Personal-Journey-Through-Anorexia-by-Christie-Pettit.pdf
    • http://xiixmcuin.linkpc.net/3204202202202/Wasted-A-Memoir-of-Anorexia-and-Bulimia-by-Marya-Hornbacher.pdf
    • http://xiixmcuin.linkpc.net/3207208206209206/Skills-Training-Manual-for-Treating-Borderline-Personality-Disorder-by-Marsha-M-Linehan.pdf
    • http://xiixmcuin.linkpc.net/3208205209205205/Rebuilding-Shattered-Lives-Treating-Complex-PTSD-and-Dissociative-Disorders-by-James-A-Chu.pdf
    • http://xiixmcuin.linkpc.net/7203207205205202/Wounded-by-Reality-Understanding-and-Treating-Adult-Onset-Trauma-by-Ghislaine-Boulanger.pdf