Malicious PDF — malware analysis report

Static analysis result for SHA-256 3becf9dee2631efd…

MALICIOUS

PDF

18.6 KB Created: 2019-11-22 07:47:02 +00:00 Authoring application: mPDF 5.7
MD5: bb80a749ec86b08350be4cc909995ef5 SHA-1: 09b553083226a43f5bc0ad26acf23f9bea39af9a SHA-256: 3becf9dee2631efd0d35fd2c90a1bbc3e02156b54127c941236b53597c997329
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM'. These links predominantly point to external PDF files with numeric slugs, suggesting a tactic to artificially inflate search engine rankings or distribute malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://icniaioobook.dumb1.com/1324132413243324832403248/The-Practical-Millwright-s-and-Engineer-s-Ready-Reckoner-by-Thomas-Dixon-Engineer-.pdf
    • http://icniaioobook.dumb1.com/132453247324332453242/The-Escapement-Engineer-Trilogy-3-by-K-J-Parker.pdf
    • http://icniaioobook.dumb1.com/132443245324532493241/My-Mummy-is-an-Engineer-by-Kerrine-Bryan.pdf
    • http://icniaioobook.dumb1.com/1324032463248324032403242/Be-a-Demolition-Engineer-by-David-Dreier.pdf
    • http://icniaioobook.dumb1.com/432433247324732413245/The-Engineer-s-Assistant-by-Adam-Middlemas.pdf
    • http://icniaioobook.dumb1.com/132433244324232463247/New-Dawn-Wandering-Engineer-1-by-Chris-Hechtl.pdf
    • http://icniaioobook.dumb1.com/53248324632423240/Devices-and-Desires-Engineer-Trilogy-1-by-K-J-Parker.pdf
    • http://icniaioobook.dumb1.com/93248324832433249/Ravages-of-War-The-Genie-and-the-Engineer-Book-3-by-Glenn-Michaels.pdf
    • http://icniaioobook.dumb1.com/132403244324332443247/Social-Engineer-Brody-Taylor-Thrillers-1-by-Ian-Sutherland.pdf
    • http://icniaioobook.dumb1.com/432443247324432433249/Inside-Jokes-Using-Humor-to-Reverse-Engineer-the-Mind-by-Matthew-M-Hurley.pdf
    • http://icniaioobook.dumb1.com/1324032483244324532473244/The-Ghost-of-the-Executed-Engineer-Technology-and-the-Fall-of-the-Soviet-Union-by-Loren-R-Graham.pdf
    • http://icniaioobook.dumb1.com/632483246324632453243/Chief-Engineer-Washington-Roebling-The-Man-Who-Built-the-Brooklyn-Bridge-by-Erica-Wagner.pdf
    • http://icniaioobook.dumb1.com/932463248324932423247/Diamond-Cut-Abs-How-to-Engineer-The-Ultimate-Six-Pack--Minimalist-Methods-for-Maximal-Results-by-Danny-Kavadlo.pdf
    • http://icniaioobook.dumb1.com/1324132413243324532453248/GST-READY-RECKONER-by-Keshav-R-Garg.pdf
    • http://icniaioobook.dumb1.com/1324132413243324732493246/The-New-Universal-Ready-Reckoner-by-J-Bettesworth.pdf
    • http://icniaioobook.dumb1.com/1324132413243324632433242/Racing-Ready-Reckoner-by-Graham-Sharpe.pdf
    • http://icniaioobook.dumb1.com/1324132413243324732493248/GST-Guide-with-Ready-Reckoner-by-Rakesh-Garg.pdf
    • http://icniaioobook.dumb1.com/1324132413243324832473240/An-Eye-on-Numbers-A-Ready-Reckoner-in-Ophthalmology-by-Anand-Shroff.pdf
    • http://icniaioobook.dumb1.com/1324132413243324632433247/Ready-Reckoner-for-Treatment-in-Pediatrics-by-Nayak-Sumitha.pdf
    • http://icniaioobook.dumb1.com/1324132413243324832463249/Ready-Reckoner-of-Base-Ball-Percentages-by-John-B-Foster.pdf