Malicious PDF — malware analysis report

Static analysis result for SHA-256 41c1f6927fb0bdea…

MALICIOUS

PDF

20.7 KB Created: 2019-05-01 19:23:21 +01:00 Authoring application: mPDF 5.7
MD5: 8335c8138b43195c9ff7859752d626d6 SHA-1: c00ef3d21ffafa6500bdb50b9db4c7e1c4edb564 SHA-256: 41c1f6927fb0bdeacf595f1a1296a2711be9f442f8261bbef2138cd47aef4ac2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by an ML classifier as malicious and contains a large number of embedded links, identified as a PDF SEO link farm. While the document body is unreadable, the heuristic suggests the primary purpose is to host or link to a large number of external PDFs. The URLs extracted are part of this link farm, and although some are marked as benign, the sheer volume and the heuristic firing indicate a malicious intent, likely for SEO manipulation or distributing further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.duckdns.org/3b23b29b24b28b20/How-to-Win-Friends-and-Influence-People-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/1b23b27b27b20b25/How-to-Win-Friends-amp-Influence-People-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/5b27b24b29b28b24/How-to-Win-Friends-and-Influence-People-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/9b28b22b24b26/How-to-Win-Friends-amp-Influence-People-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/1b21b28b27b20b27b22/How-to-Win-Friends-and-Influence-People-Cedar-Books-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/7b23b22b20b22b29/How-to-Win-Friends-and-Influence-People-A-Cedar-Book-No-6-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/7b24b26b25b22b27/HOW-TO-WIN-FRIENDS-AND-INFLUENCE-PEOPLE-From-the-Greatest-Motivational-Speaker-of-20th-Century-and-Creator-of-The-Quick-and-Easy-Way-to-Effective-Speaking-amp-How-to-Stop-Worrying-and-Start-Living-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/9b28b22b20b22b23/Der-Erfolg-Ist-In-Dir-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/4b27b26b21b20b28/Lincoln-the-Unknown-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/3b20b27b20b24b20/The-Art-of-Public-Speaking-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/4b24b25b21b23/How-to-Stop-Worrying-and-Start-Living-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/7b20b29b20b25b22/Comment-se-faire-des-amis-l-re-num-rique-D-veloppement-personnel-by-Dale-Carnegie.pdf
    • http://cmeinasaoo.duckdns.org/8b25b24b21b28/How-to-Talk-Dirty-and-Influence-People-by-Lenny-Bruce.pdf
    • http://cmeinasaoo.duckdns.org/4b29b25b25b26b29/How-To-Talk-Dirty-And-Influence-People-by-Lenny-Bruce.pdf
    • http://cmeinasaoo.duckdns.org/1b20b27b21b21b25b24/Psychology-69-Powerful-Ways-to-Influence-and-Control-People-by-Hans-Zimmerman.pdf
    • http://cmeinasaoo.duckdns.org/7b27b25b20b23b20/Manipulation-Proven-Manipulation-Techniques-To-Influence-People-With-NLP-Mind-Control-and-Persuasion-by-Pete-Martin.pdf
    • http://cmeinasaoo.duckdns.org/3b26b29b29b26b24/Key-Person-of-Influence-Revised-Edition-The-Five-Step-Method-to-become-one-of-the-most-highly-valued-and-highly-paid-people-in-your-industry-by-Daniel-Priestley.pdf
    • http://cmeinasaoo.duckdns.org/3b29b20b22b26b26/Influence-of-Love-Influence-Shorts-1-by-Patricia-Lynne.pdf
    • http://cmeinasaoo.duckdns.org/2b23b23b22b20b27/Influence-Influence-1-by-David-R-Bernstein.pdf
    • http://cmeinasaoo.duckdns.org/1b20b29b23b27b22b22/Carnegie-Institution-of-Washington-Publication-Volume-No-118-No-118-by-Carnegie-Institution-of-Washington.pdf
    • http://cmeinasaoo.duckdns.org/9b28b