Malicious PDF — malware analysis report

Static analysis result for SHA-256 13c396f6b30e437f…

MALICIOUS

PDF

24.1 KB Created: 2019-05-01 18:49:51 +01:00 Authoring application: mPDF 5.7
MD5: 1164a00d12c97b51c7b1c8bb3055d34c SHA-1: e5f9ad3b51360b4622cfdf78c308d02f2d3be2b3 SHA-256: 13c396f6b30e437f1105192cc017bd606742d0574c1782d47686c3cc139990c1
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. These URLs are presented as links to book PDFs, likely a lure to disguise malicious intent. The ML classifier also flagged this PDF as malicious, supporting the assessment of a malicious link farm attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200201208205204201/Bach-Flower-Therapy-The-Complete-Approach-by-Mechthild-Scheffer.pdf
    • http://xiixmcuin.linkpc.net/1200201208202208204/Mechthild-of-Magdeburg-The-Flowing-Light-of-the-Godhead-The-Revelations-of-Mechthild-of-Magdeburg-by-Mechthild-of-Magdeburg.pdf
    • http://xiixmcuin.linkpc.net/3208206204209204/The-Gestalt-Approach-and-Eye-Witness-to-Therapy-by-Frederick-Salomon-Perls.pdf
    • http://xiixmcuin.linkpc.net/1200201208205201202/Mechthild-of-Hackeborn-The-Book-of-Special-Grace-by-Mechthild.pdf
    • http://xiixmcuin.linkpc.net/7208202203208206/Cognitive-Behavioral-Therapy-for-Adult-ADHD-An-Integrative-Psychosocial-and-Medical-Approach-by-J-Russell-Ramsay.pdf
    • http://xiixmcuin.linkpc.net/6209209200200203/INTEGRATING-Experiential-and-Brief-Therapy-How-To-Do-Deep-Therapy---Briefly-and-How-To-Do-Brief-Therapy---Deeply-by-Ken-MacDonald.pdf
    • http://xiixmcuin.linkpc.net/6203209202200201/Jonathan-Livingston-Seagull-The-New-Complete-Edition-by-Richard-Bach.pdf
    • http://xiixmcuin.linkpc.net/1201206200204200202/Estrogen-A-Complete-Guide-to-Menopause-and-Hormone-Replacement-Therapy-by-Lila-E-Nachtigall.pdf
    • http://xiixmcuin.linkpc.net/1200201208204205208/Mechthild-Fr-lich-spirit-of-colours-by-Mechthild-Fr-lich.pdf
    • http://xiixmcuin.linkpc.net/4208207203205/The-Seeing-Eye-by-Victor-B-Scheffer.pdf
    • http://xiixmcuin.linkpc.net/1200201208202208205/Meditations-from-Mechthild-of-Magdeburg-by-Mechthild-of-Magdeburg.pdf
    • http://xiixmcuin.linkpc.net/8204205209204205/Bach-Chorales-for-Strings-28-Chorales-For-String-Bass-by-Johann-Sebastian-Bach.pdf
    • http://xiixmcuin.linkpc.net/1201208207203205203/Gewasser-in-Wuppertal-Dussel-Wupper-Liste-Der-Gewasser-in-Wuppertal-Morsbach-Deilbach-Bendahler-Bach-Mirker-Bach-Beyenburger-Stausee-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/9204201200204208/All-the-Missing-Souls-A-Personal-History-of-the-War-Crimes-Tribunals-by-David-Scheffer.pdf
    • http://xiixmcuin.linkpc.net/1203208204205203/A-Cancer-Therapy-Results-of-Fifty-Cases-and-the-Cure-of-Advanced-Cancer-by-Diet-Therapy-by-Max-Gerson.pdf
    • http://xiixmcuin.linkpc.net/1201201203208201203/Untying-the-Karmic-Knot-Healing-Through-Past-Life-Regression-Therapy-Knowledge-Through-Life-Between-Lives-Therapy-the-Earth-s-Future-Through-by-Diane-Morrin.pdf
    • http://xiixmcuin.linkpc.net/9204209201204202/The-Entire-Richard-Bach-Collection-by-Richard-Bach.pdf
    • http://xiixmcuin.linkpc.net/1208208205204206/Little-Wild-Flower-Book-One-Little-Wild-Flower-1-by-Samantha-Bayarr.pdf
    • http://xiixmcuin.linkpc.net/3202201203204203/The-Bone-Flower-Throne-The-Bone-Flower-Trilogy-1-by-T-L-Morganfield.pdf
    • http://xiixmcuin.linkpc.net/5203208201208206/Soeur-Th-r-se-of-Lisieux-The-Little-Flower-of-Jesus-A-new-and-complete-translation-of-l-Histoire-d-une-me-with-an-account-of-some-favours-attributed-to-the-intercession-of-Soeur-Th-r-se-by-Th-r-se-de-Lisieux.pdf