Malicious PDF — malware analysis report

Static analysis result for SHA-256 3155ead531dbfa6b…

MALICIOUS

PDF

18.2 KB Created: 2019-05-01 19:32:32 +01:00 Authoring application: mPDF 5.7
MD5: b098400d9f6653a8c1959edba5449193 SHA-1: 5bf8ac32716e6177a64d3e5ef22289e93800d060 SHA-256: 3155ead531dbfa6bc6f980c945802a5dd242973375772aab0516975bab9a4fa6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a dynamic DNS domain hosting numerous PDF files, likely as a lure or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.duckdns.org/4b24b22b21b29b22/Rebel-Moms-The-Off-Road-Map-for-the-Off-Road-Mom-by-Davina-Rhine.pdf
    • http://cmeinasaoo.duckdns.org/2b20b28b29b21b20/Rebel-Buddha-On-the-Road-to-Freedom-by-Dzogchen-Ponlop.pdf
    • http://cmeinasaoo.duckdns.org/1b22b22b20b25b27/Where-The-Rebel-Flag-Still-Waves-Long-Road-Home-1-by-Zoey-Marcel.pdf
    • http://cmeinasaoo.duckdns.org/4b20b27b20b25/In-Search-of-Captain-Zero-A-Surfer-s-Road-Trip-Beyond-the-End-of-the-Road-by-Allan-C-Weisbecker.pdf
    • http://cmeinasaoo.duckdns.org/3b25b29b23b23b28/Road-to-Redemption-Zombie-Road-4-by-David-A-Simpson.pdf
    • http://cmeinasaoo.duckdns.org/6b23b28b25b28b20/Road-Novels-1957-1960-On-the-Road-The-Dharma-Bums-The-Subterraneans-Tristessa-Lonesome-Traveler-Journal-Selections-by-Jack-Kerouac.pdf
    • http://cmeinasaoo.duckdns.org/9b29b22b26b23/It-s-a-Mad-Mad-Mad-Mad-Trip-On-the-Road-of-the-Longest-Two-Week-Family-Road-Trip-in-History-by-Kevin-J-Shay.pdf
    • http://cmeinasaoo.duckdns.org/1b20b26b27b22b25/Walking-Wolf-Road-The-Wolf-Road-Chronicles-1-by-Brandon-M-Herbert.pdf
    • http://cmeinasaoo.duckdns.org/2b29b21b29b20b24/Walking-Wolf-Road-The-Wolf-Road-Chronicles-1-by-Brandon-M-Herbert.pdf
    • http://cmeinasaoo.duckdns.org/1b29b28b24b26b27/Down-a-Lost-Road-The-Lost-Road-Chronicles-1-by-J-Leigh-Bralick.pdf
    • http://cmeinasaoo.duckdns.org/9b28b29b24b27/On-Herring-Cove-Road-Mr-Rosen-and-His-43Lb-Anxiety-Herring-Cove-Road-1-by-Michael-Kroft.pdf
    • http://cmeinasaoo.duckdns.org/6b25b22b26b20/Vengeance-Road-Vengeance-Road-1-by-Erin-Bowman.pdf
    • http://cmeinasaoo.duckdns.org/4b26b21b24b25b28/Demon-Road-Demon-Road-1-by-Derek-Landy.pdf
    • http://cmeinasaoo.duckdns.org/1b25b24b23/Demon-Road-Demon-Road-1-by-Derek-Landy.pdf
    • http://cmeinasaoo.duckdns.org/4b23b27b26b28/The-Wild-Road-The-Wild-Road-1-by-Gabriel-King.pdf
    • http://cmeinasaoo.duckdns.org/2b27b20b23b21b28/Abby-Road-Abby-Road-1-by-Ophelia-London.pdf
    • http://cmeinasaoo.duckdns.org/1b23b26b20b26/Rules-of-the-Road-Rules-of-the-Road-1-by-Joan-Bauer.pdf
    • http://cmeinasaoo.duckdns.org/3b23b25b27b29b28/Ten-Beach-Road-Ten-Beach-Road-1-by-Wendy-Wax.pdf
    • http://cmeinasaoo.duckdns.org/2b25b25b26b24b25/The-Road-That-Has-No-End-by-Tim-Travis.pdf
    • http://cmeinasaoo.duckdns.org/3b21b25b25b27b21/On-the-Noodle-Road-by-Jen-Lin-Liu.pdf
    • http://cmeinasaoo.duckdns.org/9b29b22b26b23/It-s-a-Mad-M