Malicious PDF — malware analysis report

Static analysis result for SHA-256 409f0fb08b9f6369…

MALICIOUS

PDF

18.3 KB Created: 2019-04-30 02:53:42 +01:00 Authoring application: mPDF 5.7
MD5: 45ec65c08c517063261b8451ccba319a SHA-1: 3da7ebdaad0ce54d11cd44826f2934e9b7ae0621 SHA-256: 409f0fb08b9f6369e1922b9b4a656b63bb95759ced809a9faf2bdfad842b589d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While the linked PDFs themselves are currently classified as benign, the overall structure and heuristic firings suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc.net/9c57c53c54c54c54/Winds-Ocean-Currents-and-Ice-Periods-Explanatory-Chapters-Concerning-Winds-Ocean-Currents-and-Frigid-Eras-by-Charles-Austin-Mendell-Taber.pdf
    • http://zacdsa.linkpc.net/1c52c56c51c53c50/The-Burning-of-Grey-by-Giselle-V-Steele.pdf
    • http://zacdsa.linkpc.net/2c53c53c55c56c59/The-Burning-Claw-The-Grey-Wolves-10-by-Quinn-Loftis.pdf
    • http://zacdsa.linkpc.net/2c54c55c59c58c59/Dark-Hearts-by-Edward-Grey.pdf
    • http://zacdsa.linkpc.net/1c58c59c50c58c58/Where-the-Wild-Winds-Are-Walking-Europe-s-Winds-from-the-Pennines-to-Provence-by-Nick-Hunt.pdf
    • http://zacdsa.linkpc.net/4c57c56c55c59/Winds-of-Fate-Valdemar-Mage-Winds-1-by-Mercedes-Lackey.pdf
    • http://zacdsa.linkpc.net/8c56c55c55c54/Winds-of-Change-Valdemar-Mage-Winds-2-by-Mercedes-Lackey.pdf
    • http://zacdsa.linkpc.net/9c57c53c53c51c51/Frigid-by-Precious-Luv.pdf
    • http://zacdsa.linkpc.net/9c57c53c53c51c52/Frigid-by-Charles-A-Jones.pdf
    • http://zacdsa.linkpc.net/8c58c51c50c56/Lord-Grey-of-the-Reform-Bill-Being-the-Life-of-Charles-Second-Earl-Grey-by-George-Macaulay-Trevelyan.pdf
    • http://zacdsa.linkpc.net/1c50c51c50c50c59/Grey-Fifty-Shades-of-Grey-as-Told-by-Christian-A-11-Minute-HOOOTTTT-summary-by-Bern-Bolo.pdf
    • http://zacdsa.linkpc.net/1c59c58c55c53c50/Frigid-Frenemy-1-by-Kate-Benson.pdf
    • http://zacdsa.linkpc.net/9c57c53c53c59c52/Frigid-Impact-by-Connie-McCarty.pdf
    • http://zacdsa.linkpc.net/9c57c53c53c59c50/Frigid-Wife-by-Orrie-Hitt.pdf
    • http://zacdsa.linkpc.net/9c57c53c54c52c56/Medius-V-The-Frigid-Wastes-by-R-W-Holmes.pdf
    • http://zacdsa.linkpc.net/9c57c53c53c50c59/Choke-Frigid-Emaciation-1-by-Serena-Siren.pdf
    • http://zacdsa.linkpc.net/9c57c53c54c52c58/The-Far-Frigid-North-Scared-Spitless-by-Patrick-Marks.pdf
    • http://zacdsa.linkpc.net/9c57c53c54c50c54/The-Cause-of-Warm-and-Frigid-Periods-by-Charles-Austin-Mendell-Taber.pdf
    • http://zacdsa.linkpc.net/2c58c51c57/Burning-Glass-Burning-Glass-1-by-Kathryn-Purdie.pdf
    • http://zacdsa.linkpc.net/9c57c53c54c53c52/Frigid-A-Daring-Funny-and-Original-Novel-by-the-Best-Selling-Author-of-The-Hourglass-Man-by-Carl-Tiktin.pdf
    • http://zacdsa.linkpc.net/9c57c53c53c51c51/Fr