Malicious PDF — malware analysis report

Static analysis result for SHA-256 266750d0d43d42ec…

MALICIOUS

PDF

21.1 KB Created: 2019-05-07 04:07:29 +01:00 Authoring application: mPDF 5.7
MD5: 2d03d9b732848c0e4370b22da3d68fc4 SHA-1: b559cbd471443dd109ac6b9cf2e34bf63bc94363 SHA-256: 266750d0d43d42ec0abd1801fc7a44b983b87f5d34523db7edd3b08df6c9f3a1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links were classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://leakscaioiobook.4dq.com/1d0c0d0c8d0c5d0c6d0c4d0c8/Difference-On-Representation-amp-Sexuality-by-Peter-Wollen.pdf
    • http://leakscaioiobook.4dq.com/1d0c0d0c8d0c5d0c5d0c0d0c9/Addressing-the-Century-100-Years-of-Art-and-Fashion-by-Peter-Wollen.pdf
    • http://leakscaioiobook.4dq.com/1d0c0d0c8d0c5d0c5d0c0d0c5/Paris-Hollywood-Writings-on-Film-by-Peter-Wollen.pdf
    • http://leakscaioiobook.4dq.com/6d0c1d0c4d0c5d0c8d0c0/The-Cinema-of-Federico-Fellini-by-Peter-Bondanella.pdf
    • http://leakscaioiobook.4dq.com/5d0c0d0c1d0c4d0c4/The-Meaning-Of-Theft-by-Peter-O-39-Mahoney.pdf
    • http://leakscaioiobook.4dq.com/6d0c7d0c5d0c6d0c7d0c6/Signs-and-Symptoms-Thomas-Pynchon-and-the-Contemporary-World-by-Peter-L-Cooper.pdf
    • http://leakscaioiobook.4dq.com/9d0c5d0c0d0c8d0c0d0c6/Swedish-cinema-from-Ingeborg-Holm-to-Fanny-and-Alexander-by-Peter-Cowie.pdf
    • http://leakscaioiobook.4dq.com/4d0c6d0c0d0c1d0c9d0c5/The-Book-of-Calamities-Five-Questions-About-Suffering-and-Its-Meaning-by-Peter-Trachtenberg.pdf
    • http://leakscaioiobook.4dq.com/4d0c5d0c4d0c0d0c6d0c0/Layers-in-Husserl-s-Phenomonology-On-Meaning-and-Intersubjectivity-by-Peter-R-Costello.pdf
    • http://leakscaioiobook.4dq.com/1d0c0d0c8d0c5d0c7d0c0d0c5/Komar-amp-Melamid-The-Fruitmarket-Gallery-Edinburgh-10-August-21-September-1985-Museum-Of-Modern-Art-Oxford-6-October-1-December-1985-by-Peter-Wollen.pdf
    • http://leakscaioiobook.4dq.com/6d0c3d0c8d0c7d0c6d0c7/Cahiers-du-Cinema-the-1960s-New-Wave-New-Cinema-Reevaluating-Hollywood-by-Jim-Hillier.pdf
    • http://leakscaioiobook.4dq.com/1d0c0d0c8d0c5d0c6d0c9d0c9/Saints-Lives-by-C-Wollen.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c0d0c4d0c8d0c3/Wir-wollen-ins-Finale-Eules-galaktischer-Moment-by-Thilo.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c2d0c3d0c4d0c3d0c4/Wir-wollen-alles-Die-gro-e-Revolte-by-Nanni-Balestrini.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c9d0c5d0c7d0c5d0c8/Wie-Sie-andere-dazu-bringen-das-zu-tun-was-Sie-wollen-by-Kishor-Sridhar.pdf
    • http://leakscaioiobook.4dq.com/1d0c0d0c8d0c5d0c5d0c8d0c3/The-Others---Sie-wollen-dein-Blut-H-amp-W-Investigations-2-by-Jess-Haines.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c0d0c4d0c8d0c4/Wir-wollen-ins-Finale-Mattis-riskantes-Spiel-by-Thilo.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c0d0c4d0c8d0c6/Wir-wollen-ins-Finale-Hardys-einmalige-Chance-by-Thilo.pdf
    • http://leakscaioiobook.4dq.com/9d0c3d0c2d0c2d0c3d0c9/Ich-Denke-Also-Spinn-Ich-Warum-Wir-Uns-Oft-Anders-Verhalten-Als-Wir-Wollen-by-Jochen-Mai.pdf
    • http://leakscaioiobook.4dq.com/4d0c2d0c2d0c2d0c8d0c4/Mama-was-wollen-diese-M-nner-Kriegsende-in-Ostdeutschland-by-Erna-Rinklin.pdf
    • http://leakscaioiobook.4dq.com/4d0c6d0c0d0c1d0c9d0c5/The-Book-of-Calamities-Five-Questions-About-Suffering-and-Its-Mean