Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ca597bf85ce47eb…

MALICIOUS

PDF

15.8 KB Created: 2019-04-30 03:27:12 +01:00 Authoring application: mPDF 5.7
MD5: 21cc02797a4d6fbcd4bc7afbda4bc36a SHA-1: e2a43620762ddc691395fe9ef1700f531f2b6b76 SHA-256: 1ca597bf85ce47eb4ff37ba2055b1670a5e8ce26ff495ed12f1c62e227c72064
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm by the PDF_SEO_LINK_FARM heuristic. This suggests the document's primary purpose is to redirect users to external sites, potentially for malicious purposes such as distributing malware or phishing. The ClamAV detection as Pdf.Dropper.Agent-7201071-0 further supports its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7201071-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7201071-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3203206207208205/The-Chase-Volume-2-The-Chase-2-by-Jessica-Wood.pdf
    • http://xiixmcuin.linkpc.net/3209200205201200/The-Chase-Volume-4-The-Chase-4-by-Jessica-Wood.pdf
    • http://xiixmcuin.linkpc.net/3203204206207203/The-Chase-Volume-1-The-Chase-1-by-Jessica-Wood.pdf
    • http://xiixmcuin.linkpc.net/2207208205200208/Chase-of-a-Lifetime-Chase-Series-1-by-Ryan-Field.pdf
    • http://xiixmcuin.linkpc.net/8203204203209/Magnus-Chase-and-the-Hammer-of-Thor-Magnus-Chase-and-the-Gods-of-Asgard-2-by-Rick-Riordan.pdf
    • http://xiixmcuin.linkpc.net/3205205208200202/Magnus-Chase-and-the-Hammer-of-Thor-Magnus-Chase-and-the-Gods-of-Asgard-2-by-Rick-Riordan.pdf
    • http://xiixmcuin.linkpc.net/1200207209203205/Chase-Tinker-and-the-House-of-Magic-Chase-Tinker-1-by-Malia-Ann-Haberman.pdf
    • http://xiixmcuin.linkpc.net/4205209200200205/Chase-Tinker-and-the-House-of-Magic-Chase-Tinker-1-by-Malia-Ann-Haberman.pdf
    • http://xiixmcuin.linkpc.net/8209204205205204/Mad-Love-Chase-Volume-3-by-Kazusa-Takashima.pdf
    • http://xiixmcuin.linkpc.net/8209204205205205/Mad-Love-Chase-Volume-4-by-Kazusa-Takashima.pdf
    • http://xiixmcuin.linkpc.net/8203208208202/The-Best-of-Elaine-Raco-Chase-A-Dream-Come-True-No-Easy-Way-Out-2-Books-in-1-by-Elaine-Raco-Chase.pdf
    • http://xiixmcuin.linkpc.net/1209208205208207/BOUND-Bound-1-by-Jessica-Chase.pdf
    • http://xiixmcuin.linkpc.net/5201205/The-One-That-Got-Away-by-Bethany-Chase.pdf
    • http://xiixmcuin.linkpc.net/8204209208204207/Chase-by-K-R-Dwyer.pdf
    • http://xiixmcuin.linkpc.net/3205203200202203/War-The-Four-Horsemen-2-by-T-A-Chase.pdf
    • http://xiixmcuin.linkpc.net/7201204202201203/The-Chase-by-Candida-Clark.pdf
    • http://xiixmcuin.linkpc.net/8200202201202/Settler-s-Chase-by-D-H-Eraldi.pdf
    • http://xiixmcuin.linkpc.net/1202201202206202/Mad-About-the-Hatter-by-Dakota-Chase.pdf
    • http://xiixmcuin.linkpc.net/3201205208203206/Death-or-Life-by-T-A-Chase.pdf
    • http://xiixmcuin.linkpc.net/2203203201204204/Freaks-in-Love-by-T-A-Chase.pdf
    • http://xiixmcuin.linkpc.net/8209204