Malicious PDF — malware analysis report

Static analysis result for SHA-256 19ab2a0ac05a76f8…

MALICIOUS

PDF

24.5 KB Created: 2019-05-01 17:19:48 +01:00 Authoring application: mPDF 5.7
MD5: 79abf10765161203abcb3f563ab01d73 SHA-1: ed21d74b8aec6dc53fe0a8d189e6820f0a8a87c5 SHA-256: 19ab2a0ac05a76f8302b69a0a80d4bdd896f0bf47f0fd26ec5eb443bc3f227df
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to seemingly benign book titles, the sheer volume and the use of a dynamic DNS hostname suggest a potential for SEO manipulation or the distribution of malicious content. The ML_NYX_PDF_MALICIOUS classifier also flagged this file with high confidence. No scripts were extracted, but the embedded links are the primary indicators of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://njcuejauiai.linkpc.net/2df5df6df8df0df4/Mindwise-How-We-Understand-What-Others-Think-Believe-Feel-and-Want-by-Nicholas-Epley.pdf
    • http://njcuejauiai.linkpc.net/9df8df7df6df8df7/Mensenkennis-en-misverstand-hoe-we-gedachten-gevoelens-en-bedoelingen-van-onszelf-en-anderen-begrijpen---of-niet-by-Nicholas-Epley.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df0df6df9/Antifragile-How-to-Live-in-a-World-We-Don-t-Understand-by-Nassim-Nicholas-Taleb.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df1df1df8/Understand-Rap-Explanations-of-Confusing-Rap-Lyrics-that-You-amp-Your-Grandma-Can-Understand-by-William-Buckholz.pdf
    • http://njcuejauiai.linkpc.net/9df6df8df0df3/Self-Compassion---I-Don-t-Have-To-Feel-Better-Than-Others-To-Feel-Good-About-Myself-Learn-How-To-See-Self-Esteem-Through-The-Lens-Of-Self-Love-and-Mindfulness-and-Cultivate-The-Courage-To-Be-You-by-Simeon-Lindstrom.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df0df7df2/Understand-Alzheimer-s-A-First-Time-Caregiver-s-Plan-to-Understand-amp-Prepare-for-Alzheimer-s-amp-Dementia-by-Callisto-Media.pdf
    • http://njcuejauiai.linkpc.net/6df1df0df1df0df1/Talking-to-Animals-How-You-Can-Understand-Animals-and-They-Can-Understand-You-by-Jon-Katz.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df1df7df3/How-to-Read-and-Understand-the-Biblical-Prophets-How-to-Read-and-Understand-the-Biblical-Prophets-by-Peter-J-Gentry.pdf
    • http://njcuejauiai.linkpc.net/1df0df0df3df2df6df5/The-Death-and-Life-of-Nicholas-Linnear-Nicholas-Linnear-6-5-by-Eric-Van-Lustbader.pdf
    • http://njcuejauiai.linkpc.net/9df0df5df1df8df5/Understand-and-Care-by-Cheri-J-Meiners.pdf
    • http://njcuejauiai.linkpc.net/4df7df8df6df1/You-Just-Don-t-Understand-Women-and-Men-in-Conversation-by-Deborah-Tannen.pdf
    • http://njcuejauiai.linkpc.net/1df1df8df5df6df7df8/How-to-Understand-Autism-The-Easy-Way-by-Alexander-Durig.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df2df3df7/How-to-Read-and-Understand-Poetry-by-Willard-Spiegelman.pdf
    • http://njcuejauiai.linkpc.net/9df1df6df5df9df3/Confessions-of-a-Dad-My-Kids-Don-t-Understand-the-Value-of-Money-by-Azhar-Laher.pdf
    • http://njcuejauiai.linkpc.net/1df4df2df8df1df5/The-J-Curve-A-New-Way-to-Understand-Why-Nations-Rise-and-Fall-by-Ian-Bremmer.pdf
    • http://njcuejauiai.linkpc.net/8df5df6df2df3df3/Easier-to-understand-the-programming-mechanism-Easy-by-Shima.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df1df6df8/Twenty-Buildings-Every-Architect-Should-Understand-by-Simon-Unwin.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df2df4df5/Understand-Good-Play-Words-Of-Consequence-by-Masaaki-Hatsumi.pdf
    • http://njcuejauiai.linkpc.net/9df1df7df7df0/In-the-Shadow-of-a-Saint-A-Son-s-Journey-to-Understand-His-Father-s-Legacy-by-Ken-Wiwa.pdf
    • http://njcuejauiai.linkpc.net/9df8df6df2df4df3/Dare-to-Dream-Understand-God-s-Design-for-Your-Life-by-Paula-White.pdf