Malicious PDF — malware analysis report

Static analysis result for SHA-256 13b704b99093e0f7…

MALICIOUS

PDF

16.1 KB Created: 2019-05-04 13:54:03 +01:00 Authoring application: mPDF 5.7
MD5: 014899b8d04e82725eb66e36e83f280f SHA-1: b544ba58ca1aecbb6ef9ab08f718687fdafcc32c SHA-256: 13b704b99093e0f7cbbf7b8bafe2c8de8297f2e08207c5dcbfe364793b985a5f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to manipulate search engine results or distribute content from these URLs. While the document body is heavily obfuscated, the presence of embedded links points towards a potential phishing or content distribution vector. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2204202203209/Captain-Marvel-Volume-1-Higher-Further-Faster-More-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/1200204205201206/Captain-Marvel-The-Death-of-Captain-Marvel-by-Jim-Starlin.pdf
    • http://xiixmcuin.linkpc.net/7203205209200200/Faster-Higher-Farther-The-Volkswagen-Scandal-by-Jack-Ewing.pdf
    • http://xiixmcuin.linkpc.net/3201204209209202/Pretty-Deadly-2-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/3203203204200209/Bitch-Planet-4-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/2209209201203204/Pretty-Deadly-1-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/8208202203204/Avengers-Assemble-Science-Bros-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/5203203202208207/The-Death-of-Captain-Marvel-by-Jim-Starlin.pdf
    • http://xiixmcuin.linkpc.net/5208209201/Bitch-Planet-Vol-2-President-Bitch-by-Kelly-Sue-DeConnick.pdf
    • http://xiixmcuin.linkpc.net/1200200207207206200/Captain-Midnight-Archives-Volume-2-Captain-Midnight-Saves-the-World-by-Bill-Woolfolk.pdf
    • http://xiixmcuin.linkpc.net/4201206205202203/Captain-Phasma-by-Kelly-Thompson.pdf
    • http://xiixmcuin.linkpc.net/1209203201207204/Ms-Marvel-Volume-1-Best-of-the-Best-by-Brian-Reed.pdf
    • http://xiixmcuin.linkpc.net/1209203203203201/Ms-Marvel-Volume-8-War-of-the-Marvels-by-Brian-Reed.pdf
    • http://xiixmcuin.linkpc.net/1201207208208202202/Marvel-Encyclopedia-Volume-2-X-Men-Hc-by-Eric-J-Moreels.pdf
    • http://xiixmcuin.linkpc.net/1204203203205205/Ms-Marvel-Volume-2-Civil-War-by-Brian-Reed.pdf
    • http://xiixmcuin.linkpc.net/1209203203203200/Ms-Marvel---Volume-7-Dark-Reign-by-Brian-Reed.pdf
    • http://xiixmcuin.linkpc.net/4200207207207209/Marvel-Zombies-The-Complete-Collection-Volume-1-by-Mark-Millar.pdf
    • http://xiixmcuin.linkpc.net/1201207209206200208/Thor-Volume-1-The-Goddess-of-Thunder-Marvel-Ultimate-Graphic-Novels-Collection-104-by-Jason-Aaron.pdf
    • http://xiixmcuin.linkpc.net/9204204200202201/Achieving-Sustainable-Cultivation-of-Rice-Volume-1-Breeding-for-Higher-Yield-and-Quality-by-Pankaj-Jaiswal.pdf
    • http://xiixmcuin.linkpc.net/6206202205207202/Captain-Nemo-Volume-1-by-Jason-DeAngelis.pdf