Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e5630f792419c7f…

MALICIOUS

PDF

18.5 KB Created: 2019-05-02 17:10:22 +01:00 Authoring application: mPDF 5.7
MD5: 8868e92e1a26e452faafe011016935bb SHA-1: 658a6a8df4c63d343ae10e3db643fcb44f65a91e SHA-256: 0e5630f792419c7f214f1a91ed860c49d946423633b9de54d977291e13ac897e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a dynamic DNS domain, identified by the 'PDF_SEO_LINK_FARM' heuristic. While many of these URLs are marked as benign, the sheer volume and the use of a dynamic DNS domain suggest a malicious intent, possibly for SEO poisoning or to distribute further payloads. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.duckdns.org/9b27b25b24b22b23/Theo-Logic-Theological-Logical-Theory-The-Spirit-Of-Truth-Theo-Logic-3-by-Hans-Urs-von-Balthasar.pdf
    • http://cmeinasaoo.duckdns.org/9b27b25b23b27b21/Theo-Drama-Theological-Dramatic-Theory-The-Action-Theo-Drama-4-by-Hans-Urs-von-Balthasar.pdf
    • http://cmeinasaoo.duckdns.org/9b27b25b23b26b26/Theo-Drama-Theological-Dramatic-Theory-Prolegomena-Theo-Drama-1-by-Hans-Urs-von-Balthasar.pdf
    • http://cmeinasaoo.duckdns.org/6b28b24b20b21b21/Our-Best-Logic-Puzzles-Logic-grid-and-table-hidden-meaning-mazes-rebus-and-syllogisms-by-Steven-D-Fields.pdf
    • http://cmeinasaoo.duckdns.org/6b21b26b26b20b21/The-Threat-Of-Logical-Mathematism-A-Study-On-The-Critique-Of-Mathematical-Logic-In-Germany-At-The-Turn-Of-The-20th-Century-by-Jarmo-Pulkkinen.pdf
    • http://cmeinasaoo.duckdns.org/9b27b25b23b22b26/Theo-Growing-Up-Fast-by-Theo-Walcott.pdf
    • http://cmeinasaoo.duckdns.org/1b23b29b21b22b24/Language-Truth-and-Logic-by-A-J-Ayer.pdf
    • http://cmeinasaoo.duckdns.org/5b28b21b20b21/Probability-Theory-The-Logic-of-Science-by-E-T-Jaynes.pdf
    • http://cmeinasaoo.duckdns.org/9b27b25b23b25b29/Theo-Jansen-The-Great-Pretender-by-Theo-Jansen.pdf
    • http://cmeinasaoo.duckdns.org/7b20b20b24b20b24/Bernanos-An-Ecclesial-Existence-by-Hans-Urs-von-Balthasar.pdf
    • http://cmeinasaoo.duckdns.org/4b25b24b23b28b27/Theo-by-Ed-Taylor.pdf
    • http://cmeinasaoo.duckdns.org/1b22b23b28b23b27/Thank-You-Theo-by-Premila-James.pdf
    • http://cmeinasaoo.duckdns.org/2b24b20b29b25b21/Come-Over-to-My-House-by-Theo-LeSieg.pdf
    • http://cmeinasaoo.duckdns.org/2b25b24b29b26b28/Ten-Apples-Up-On-Top-by-Theo-LeSieg.pdf
    • http://cmeinasaoo.duckdns.org/3b21b25b25b24b28/Ten-Apples-Up-on-Top-by-Theo-LeSieg.pdf
    • http://cmeinasaoo.duckdns.org/1b25b24b28b24b28/Godonism-by-Theo-Von-Cezar.pdf
    • http://cmeinasaoo.duckdns.org/4b20b25b28b21b22/The-Carrot-Man-by-Theo-A-Gerken.pdf
    • http://cmeinasaoo.duckdns.org/1b24b27b24b23b23/Transgression-by-Theo-Fenraven.pdf
    • http://cmeinasaoo.duckdns.org/1b21b22b21b25b26b29/The-Kaisers-by-Theo-Aronson.pdf
    • http://cmeinasaoo.duckdns.org/3b26b21b29b23b23/Imaginary-Logic-by-Rodney-Jones.pdf