Malicious PDF — malware analysis report

Static analysis result for SHA-256 4afbbd865cd3f488…

MALICIOUS

PDF

17.7 KB Created: 2019-05-01 17:11:58 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-13
MD5: ae72defe9453145e82264670101e9a81 SHA-1: b6dfd4428dd316e6a4111f49526ca0bfa0a394e5 SHA-256: 4afbbd865cd3f4888c3b078d534a5f357f5800dd0c7a3b201603a67cde5e6660
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. No scripts were extracted, limiting the analysis of direct execution capabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7200202200202/Gone-Wild-An-Endangered-Animal-Alphabet-by-David-McLimans.pdf In PDF document text
    • http://xiixmcuin.linkpc.net/4207209203207206/A-Is-For-Alligator-B-Is-For-Bear-Animal-Alphabet-The-Alphabet-Series-1-by-N-V-Smith.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/4203207200209208/Zoo-Vet-Adventures-Of-A-Wild-Animal-Doctor-by-David-Taylor.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/8205203204205202/African-Animal-Alphabet-by-Beverly-Joubert.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/4201207208208204/The-Last-Speakers-The-Quest-to-Save-the-World-s-Most-Endangered-Languages-by-K-David-Harrison.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/8209204201203202/Weird-Wild-Animal-Facts-by-Sherry-Seethaler.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/3203201201200201/G-Is-for-Googol-A-Math-Alphabet-Book-by-David-M-Schwartz.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2203209204204203/Letter-Perfect-The-Marvelous-History-of-Our-Alphabet-From-A-to-Z-by-David-Sacks.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/4209205201206207/Animal-Kingdom-by-David-Burnie.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/5202207206202204/The-Kingfisher-Animal-Encyclopedia-by-David-Burnie.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/7207202201204203/F-est-pour-le-Fran-ais-Un-Livre-d-Alphabet-sur-le-Qu-bec-F-Is-for-French-A-Quebec-Alphabet-by-Elaine-Arsenault.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/5202207205205207/The-Kingfisher-Illustrated-Animal-Encyclopedia-by-David-Burnie.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2201204206208/Spillover-Animal-Infections-and-the-Next-Human-Pandemic-by-David-Quammen.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2205208204208201/The-Trials-of-Life-A-Natural-History-of-Animal-Behaviour-by-David-Attenborough.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/1207207208202206/Wet-amp-Wild-by-David-Ellis.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/1208203204200207/The-Unheeded-Cry-Animal-Consciousness-Animal-Pain-And-Science-by-Bernard-E-Rollin.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2203208208207204/Animal-Watching-A-New-Guide-to-the-Animal-World-by-Desmond-Morris.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/4209207204205/Wild-Civility-by-David-Biespiel.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/1208203203209207/Critical-Animal-Studies-Reader-An-Introduction-to-an-Intersectional-Social-Justice-Approach-to-Animal-Liberation-by-Anthony-J-Nocella-II.pdfIn PDF document text
    • http://xiixmcuin.linkpc.net/2205206208207/Animal-Attraction-Animal-Magnetism-2-by-Jill-Shalvis.pdfIn PDF document text