Malicious PDF — malware analysis report

Static analysis result for SHA-256 093e9481b6500a76…

MALICIOUS

PDF

16.0 KB Created: 2019-04-30 02:34:56 +01:00 Authoring application: mPDF 5.7
MD5: e553f991f3d9998a4a5d33fe532106d6 SHA-1: ba8e6c6198271e484d896e1560ad1a1a8fc02747 SHA-256: 093e9481b6500a76759fedc40788490ea1f8753343b078bf7d2649a561af736d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent to manipulate search engine results or redirect users to potentially harmful content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8203207209204204/Norv-ge-3---Bergen-et-les-fjords-du-Sud-Ouest-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/6208208201208203/Ouest-am-ricain-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/9201202205200205/Lonely-Planet-The-World-A-Traveller-s-Guide-to-the-Planet-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/1200209208201204202/Lonely-Planet-s-Ultimate-Travel-Our-List-of-the-500-Best-Places-to-See-Ranked-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/5209201206203202/Lonely-Planet-Naples-Pompeii-amp-the-Amalfi-Coast-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/9202200209203209/Lonely-Planet-Sri-Lanka-Phrasebook-Lonely-Planet-Phrasebook-India-by-Margit-Meinhold.pdf
    • http://xiixmcuin.linkpc.net/9206205207208201/Lonely-Planet-Japan-Tokyo-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/3205204205203204/Lonely-Planet-Walking-in-Spain-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/4203208209200200/Wales-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/8203207206207207/Norv-ge-3---Oslo-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/1201204207203206209/Lonely-Planet-Reisef-hrer-Irland-by-Fionn-Davenport.pdf
    • http://xiixmcuin.linkpc.net/4204205204207207/City-Trails---Paris-by-Lonely-Planet-Kids.pdf
    • http://xiixmcuin.linkpc.net/7200208202205206/Lonely-Planet-Bushwalking-in-Papua-New-Guinea-by-Yvon-Perusse.pdf
    • http://xiixmcuin.linkpc.net/3208203203208202/Thailand-Vietnam-Laos-amp-Cambodia-Travel-Atlas-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/6200203206208207/Lonely-Planet-Ethiopia-Djibouti-Somaliland-by-Jean-Bernard-Carillet.pdf
    • http://xiixmcuin.linkpc.net/1201200205206202207/Fjords-Review-Volume-2-Issue-2-by-Fjords-Review.pdf
    • http://xiixmcuin.linkpc.net/4203207202205208/Unpacked-Travel-Disaster-Stories-by-Tony-Wheeler-and-Other-Lonely-Planet-Authors-by-Tony-Wheeler.pdf
    • http://xiixmcuin.linkpc.net/8204204206203204/Maroc-9---Comprendre-le-Maroc-et-Maroc-pratique-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/6208208202209203/Made-in-Sud-Ouest-by-Corinne-Jausserand.pdf
    • http://xiixmcuin.linkpc.net/1201200205206205207/Fjords-in-Canada-by-Jesse-Russell.pdf