Malicious PDF — malware analysis report

Static analysis result for SHA-256 4464a57d69e5321d…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 04:17:24 +01:00 Authoring application: mPDF 5.7
MD5: fdd5707fae41b9159c7907fe95fdf0c6 SHA-1: e9e7e591735eb4992c06f4380baafcf7d8199562 SHA-256: 4464a57d69e5321dc373d04bfd63f26bc7eea80fafc05d4e68b97462a2005a47
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a link farm by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern involves directing users to a multitude of external URLs, likely for malicious purposes such as phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/6201205203202201/Facts-Of-Life-by-Pippo-Lionni.pdf
    • http://xiixmcuin.linkpc.net/1201200206200207200/Pippi-Pack-2-Books-quot-Pippi-Longstocking-quot-and-quot-Pippi-Goes-on-Board-quot-by-Astrid-Lindgren.pdf
    • http://xiixmcuin.linkpc.net/6201205202200202/Leo-Lionni-A-Passion-for-Creativity-by-Leo-Lionni.pdf
    • http://xiixmcuin.linkpc.net/6201205202200204/Leo-Lionni-s-Little-Mice-Tales-by-Leo-Lionni.pdf
    • http://xiixmcuin.linkpc.net/4207206206201204/The-Facts-of-Life-by-R-D-Laing.pdf
    • http://xiixmcuin.linkpc.net/7202203200208205/Patient-Drug-Facts-2004-Published-by-Facts-and-Comparisons-by-Timothy-R-Covington.pdf
    • http://xiixmcuin.linkpc.net/7201207207206205/Random-Facts-1869-Facts-To-Make-You-Want-To-Learn-More-by-Nazar-Shevchenko.pdf
    • http://xiixmcuin.linkpc.net/7203208203201207/Invincible-Vol-5-The-Facts-of-Life-by-Robert-Kirkman.pdf
    • http://xiixmcuin.linkpc.net/7207200201202208/Colorless-Tsukuru-Tazaki-and-His-Years-of-Pilgrimage---101-Book-Facts-1-Fun-Facts-amp-Trivia-Tidbits-by-G-Whiz.pdf
    • http://xiixmcuin.linkpc.net/7205204205203200/Americanah-by-Chimamanda-Ngozi-Adichie-Top-50-Facts-Coutndown-by-Top-50-Facts.pdf
    • http://xiixmcuin.linkpc.net/8206202207208205/Creation-Facts-Of-Life-Revisited-Pb-by-Gary-E-Parker.pdf
    • http://xiixmcuin.linkpc.net/1209209207202203/The-Facts-of-Life-and-Other-Dirty-Jokes-by-Willie-Nelson.pdf
    • http://xiixmcuin.linkpc.net/5202200202205204/The-New-Corporate-Facts-of-Life-Rethink-Your-Business-to-Transform-Today-s-Challeneges-Into-Tomorrow-s-Profits-by-Diana-Rivenburgh.pdf
    • http://xiixmcuin.linkpc.net/3201208209208209/Animal-Butts-amp-Facts-Too-Fun-Animal-Books-for-Kids-With-Facts-amp-Incredible-Photos-Exploring-Our-Incredible-World-Children-s-Book-Series-by-Mark-Smith.pdf
    • http://xiixmcuin.linkpc.net/1201200205209201207/Pippi-On-The-Run-by-Astrid-Lindgren.pdf
    • http://xiixmcuin.linkpc.net/1201200205209207208/Pippi-Longstocking-4-by-Astrid-Lindgren.pdf
    • http://xiixmcuin.linkpc.net/2203205208201201/Pippi-Longstocking-by-Astrid-Lindgren.pdf
    • http://xiixmcuin.linkpc.net/4207204201201/Pippi-Goes-on-Board-by-Astrid-Lindgren.pdf
    • http://xiixmcuin.linkpc.net/3202204206209/Pippi-Longstocking-by-Astrid-Lindgren.pdf
    • http://xiixmcuin.linkpc.net/2205205203206203/Do-You-Know-Pippi-Longstocking-by-Astrid-Lindgren.pdf
    • http://xiixmcuin.linkpc.net/7207200201202208/Colorless-Tsukuru-Tazaki-and-His-Years-of-Pilgrimag