Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e579c5b14a6b7c0…

MALICIOUS

PDF

20.9 KB Created: 2019-05-02 03:28:14 +01:00 Authoring application: mPDF 5.7
MD5: 1ea1030a7ac87b98ff5f37161a667ef8 SHA-1: 3f51adfdbcf8d713e674532b338ee35702c2f460 SHA-256: 0e579c5b14a6b7c096b5e3a51f4866f2db275b377a57dd74bb354e092b2149ef
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 25 external PDF links, suggesting a tactic to drive traffic or potentially distribute further malicious content. While the URLs themselves are currently marked as benign, the overall structure and heuristic firings strongly suggest a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/6200204206208/Love-Triangle-Ronald-Reagan-Jane-Wyman-and-Nancy-Davis----All-the-Gossip-Unfit-to-Print-Blood-Moon-s-Babylon-Series-by-Darwin-Porter.pdf
    • http://xiixmcuin.linkpc.net/1204203206203205/I-Love-You-Ronnie-The-Letters-of-Ronald-Reagan-to-Nancy-Reagan-by-Nancy-Reagan.pdf
    • http://xiixmcuin.linkpc.net/4202200207209202/The-Notes-Ronald-Reagan-s-Private-Collection-of-Stories-and-Wisdom-by-Ronald-Reagan.pdf
    • http://xiixmcuin.linkpc.net/3202202209205201/A-Shining-City-The-Legacy-of-Ronald-Reagan-by-Ronald-Reagan.pdf
    • http://xiixmcuin.linkpc.net/3202202209205203/The-Greatest-Speeches-of-Ronald-Reagan-by-Ronald-Reagan.pdf
    • http://xiixmcuin.linkpc.net/3202202209204207/Ronald-Reagan-Talks-To-America-by-Ronald-Reagan.pdf
    • http://xiixmcuin.linkpc.net/1204204200206203/The-Reagan-Diaries-by-Ronald-Reagan.pdf
    • http://xiixmcuin.linkpc.net/1201206208200203202/Blood-Moon-Blood-Series-2-by-T-Lynne-Tolles.pdf
    • http://xiixmcuin.linkpc.net/3207200207207202/An-American-Life-by-Ronald-Reagan.pdf
    • http://xiixmcuin.linkpc.net/1200209207206/Take-Me-Cowboy-Love-on-Chance-Avenue-1-75th-Copper-Mountain-Rodeo-4-by-Jane-Porter.pdf
    • http://xiixmcuin.linkpc.net/5200205203201205/Abortion-amp-the-Conscience-of-the-Nation-by-Ronald-Reagan.pdf
    • http://xiixmcuin.linkpc.net/7207200200204201/Articles-on-Juvenile-Series-Including-Tom-Swift-Nancy-Drew-Tom-Swift-Jr-the-Dana-Girls-Goosebumps-Alex-Rider-the-Mad-Scientists-Club-Everworld-Gossip-Girl-Bobbsey-Twins-Danny-Dunn-Remnants-Rover-Boys-Three-Investigators-by-Hephaestus-Books.pdf
    • http://xiixmcuin.linkpc.net/3206208205201206/Rawhide-Down-The-Near-Assassination-of-Ronald-Reagan-by-Del-Quentin-Wilber.pdf
    • http://xiixmcuin.linkpc.net/2201207209206207/Dutch-A-Memoir-of-Ronald-Reagan-by-Edmund-Morris.pdf
    • http://xiixmcuin.linkpc.net/1204200203202201/The-Rebellion-of-Ronald-Reagan-A-History-of-the-End-of-the-Cold-War-by-James-Mann.pdf
    • http://xiixmcuin.linkpc.net/1200205203203208208/Frommer-s-London-2008-by-Darwin-Porter.pdf
    • http://xiixmcuin.linkpc.net/1200205203205202207/Frommer-s-England-2008-by-Darwin-Porter.pdf
    • http://xiixmcuin.linkpc.net/5209200208209207/Rendezvous-with-Destiny-Ronald-Reagan-and-the-Campaign-That-Changed-America-by-Craig-Shirley.pdf
    • http://xiixmcuin.linkpc.net/1201202206202201201/Making-of-the-Postmodern-Presidency-From-Ronald-Reagan-to-Barack-Obama-by-John-F-Freie.pdf
    • http://xiixmcuin.linkpc.net/6200207207202/Jacqueline-Kennedy-Onassis-A-Life-Beyond-Her-Wildest-Dreams-by-Darwin-Porter.pdf