Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c163c8dcd8f75c3…

MALICIOUS

PDF

22.2 KB Created: 2019-05-01 19:21:08 +01:00 Authoring application: mPDF 5.7
MD5: 1651c987e3685576746d7b91fbfae179 SHA-1: ace1d187dfde4f3974e1f9903e1b75329a0f6f88 SHA-256: 3c163c8dcd8f75c333c29152badf87f0e58e9f9cfb3dc1c3e89846730893e6de
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a large number of embedded URLs pointing to external PDF documents hosted on a dynamic DNS domain. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.duckdns.org/2b20b29b21b27b26/The-Japanese-Devil-Fish-Girl-and-Other-Unnatural-Attractions-Japanese-Devil-Fish-Girl-1-by-Robert-Rankin.pdf
    • http://cmeinasaoo.duckdns.org/1b20b25b24b22b21b27/The-sweet-memory-with-japanese-most-cute-girl-She-is-very-cute-and-sexy-by-king-of-japanese-paparazzi.pdf
    • http://cmeinasaoo.duckdns.org/1b20b25b24b21b23b23/Most-beautiful-woman-makes-my-junior-stand-up-Playing-lovely-sex-with-japanese-cute-amateure-girl-by-Playing-lovely-sex-with-japanese-cute-amateure-girl.pdf
    • http://cmeinasaoo.duckdns.org/1b21b26b29b27b27b26/Fish---Noch-mehr-Fish---F-r-immer-Fish-Dreimal-ungew-hnliche-Motivation-in-einem-Band-by-Stephen-C-Lundin.pdf
    • http://cmeinasaoo.duckdns.org/1b27b23b21b24b23/The-Fish-Girl-by-Mirandi-Riwoe.pdf
    • http://cmeinasaoo.duckdns.org/3b20b22b29b24b29/Fish-Girl-by-David-Wiesner.pdf
    • http://cmeinasaoo.duckdns.org/1b22b26b25b20b24/Salt-Fish-Girl-by-Larissa-Lai.pdf
    • http://cmeinasaoo.duckdns.org/4b27b22b26b23b22/Red-Fish-Dead-Fish-Fish-Out-of-Water-2-by-Amy-Lane.pdf
    • http://cmeinasaoo.duckdns.org/2b24b20b28b23b20/The-American-Diary-of-a-Japanese-Girl-by-Yone-Noguchi.pdf
    • http://cmeinasaoo.duckdns.org/1b20b25b24b22b22b20/Hiroko-Kumada-is-look-like-a-japanese-famous-idol-and-she-was-massaged-with-electric-vibration-paparazzi-of-japanese-amateure-by-king-of-japanese-paparazzi.pdf
    • http://cmeinasaoo.duckdns.org/1b26b27b27b21b27/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://cmeinasaoo.duckdns.org/4b27b22b27b27b21/A-Few-Good-Fish-Fish-Out-of-Water-3-by-Amy-Lane.pdf
    • http://cmeinasaoo.duckdns.org/1b27b29b20b23/Jimi-s-Book-of-Japanese-A-Motivating-Method-to-Learn-Japanese-by-Peter-X-Takahashi.pdf
    • http://cmeinasaoo.duckdns.org/8b28b29b23b20b22/Survival-Japanese-How-to-Communicate-without-Fuss-or-Fear-Instantly-Japanese-Phrasebook-by-Boy-Lafayette-de-Mente.pdf
    • http://cmeinasaoo.duckdns.org/6b24b27b20b28b24/The-Anime-Companion-What-s-Japanese-in-Japanese-Animation-by-Gilles-Poitras.pdf
    • http://cmeinasaoo.duckdns.org/6b24b27b20b28b28/The-Anime-Companion-2-More-What-s-Japanese-in-Japanese-Animation-by-Gilles-Poitras.pdf
    • http://cmeinasaoo.duckdns.org/3b21b20b21b27b28/Japanese-Cooking-Made-Simple-A-Japanese-Cookbook-with-Authentic-Recipes-for-Ramen-Bento-Sushi-amp-More-by-Salinas-Press.pdf
    • http://cmeinasaoo.duckdns.org/5b26b21b24b21b27/Japanese-wife-Mayumi-by-king-of-japanese-paparazzi.pdf
    • http://cmeinasaoo.duckdns.org/1b26b26b24b26/The-Fugitive-by-Robert-L-Fish.pdf
    • http://cmeinasaoo.duckdns.org/4b27b29b22b23b29/Inside-and-Other-Short-Fiction-Japanese-Women-by-Japanese-Women-by-Cathy-Layne.pdf
    • http://cmeinasaoo.duckdns.org/1b21b26b29b27b27b26/Fish---Noch-mehr-Fish---F-r-immer-Fi