Malicious PDF — malware analysis report

Static analysis result for SHA-256 13bff980e76b4252…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 01:57:18 +01:00 Authoring application: mPDF 5.7
MD5: 85e71e1f6aae9233c1ec3df6ca0b7999 SHA-1: dc0360dcae0c53a4f412ad423bb992f1f5336515 SHA-256: 13bff980e76b42528cc64a51b115033ca2031928f28042e6b46015e2d918ab34
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which suggests an attempt to direct users to external content. While the URLs themselves are labeled as benign, the sheer volume and the heuristic firing indicate a malicious intent, likely to distribute further malicious content or engage in SEO-based spam. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200200200201203208/Hearing-the-Voice-of-the-Market-Competitive-Advantage-Through-Creative-Use-of-Market-Information-by-Vincent-Barabba.pdf
    • http://xiixmcuin.linkpc.net/1209203206206208/Is-That-Really-You-God-Hearing-the-Voice-of-God-by-Loren-Cunningham.pdf
    • http://xiixmcuin.linkpc.net/7202203207206200/Tune-In-Hearing-God-s-Voice-Through-the-Static-by-Jen-Hatmaker.pdf
    • http://xiixmcuin.linkpc.net/4205200207209203/Hearing-Her-Voice-A-Case-for-Women-Giving-Sermons-by-John-Dickson.pdf
    • http://xiixmcuin.linkpc.net/6207208203203200/Define-Your-Voice-Narrowing-Down-Your-Target-Market-by-Altovise-Pelzer.pdf
    • http://xiixmcuin.linkpc.net/6203200202205207/Predict-the-Next-Bull-or-Bear-Market-and-Win-How-to-Use-Key-Indicators-to-Profit-in-Any-Market-by-Michael-Sincere.pdf
    • http://xiixmcuin.linkpc.net/1200200200204202208/Da-Barabba-a-Ges-Convertito-da-uno-sguardo-by-Pietro-Sarubbi.pdf
    • http://xiixmcuin.linkpc.net/9204205200205202/Belt-Voice-Training---Singing-with-a-belting-voice-by-Christin-Bonin.pdf
    • http://xiixmcuin.linkpc.net/3202204202209200/Set-Your-Voice-Free-How-To-Get-The-Singing-Or-Speaking-Voice-You-Want-by-Roger-Love.pdf
    • http://xiixmcuin.linkpc.net/1201208203204208208/Voice-of-Fire-Voice-of-Earth-by-Shiho-Kanzaki.pdf
    • http://xiixmcuin.linkpc.net/6205207208201202/Day-Trading-and-Swing-Trading-the-Currency-Market-Technical-and-Fundamental-Strategies-to-Profit-from-Market-Moves-by-Kathy-Lien.pdf
    • http://xiixmcuin.linkpc.net/7207208209204204/Voice-Over-Voice-Actor-What-It-s-Like-Behind-the-Mic-by-Yuri-Lowenthal.pdf
    • http://xiixmcuin.linkpc.net/4205204207204201/The-Meat-Market-Series-Boxed-Set-Meat-Market-1-3-by-Baylee-Crush.pdf
    • http://xiixmcuin.linkpc.net/4206201209202206/A-Silent-Voice-Volume-2-A-Silent-Voice-2-by-Yoshitoki-Oima.pdf
    • http://xiixmcuin.linkpc.net/8204208/A-Silent-Voice-Volume-1-A-Silent-Voice-1-by-Yoshitoki-Oima.pdf
    • http://xiixmcuin.linkpc.net/4206202201203203/A-Silent-Voice-Volume-3-A-Silent-Voice-3-by-Yoshitoki-Oima.pdf
    • http://xiixmcuin.linkpc.net/4205208203205201/Hearing-Love-by-Katie-Lee.pdf
    • http://xiixmcuin.linkpc.net/3200208208202201/Controlled-by-His-Voice-Box-Set-Controlled-by-His-Voice-1-5-by-Skylar-Cross.pdf
    • http://xiixmcuin.linkpc.net/2203209207207201/The-Hearing-Trumpet-by-Leonora-Carrington.pdf
    • http://xiixmcuin.linkpc.net/1200200209201204202/Disorders-of-Hearing-by-Brad-A-Stach.pdf