Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b5d26cdb8307c12…

MALICIOUS

PDF

20.7 KB Created: 2019-04-30 04:22:07 +01:00 Authoring application: mPDF 5.7
MD5: 18529b8159dc8e283606253d78b819ba SHA-1: ee3d66c52fc41669cd69792445c3fe600bc10595 SHA-256: 4b5d26cdb8307c122797848c2f366652d922ff50ff971795e0c38ff680b12fb3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, masquerading as academic papers, which are likely intended to redirect users to malicious content. The PDF_SEO_LINK_FARM heuristic specifically identified this behavior, indicating a link farm designed to attract clicks. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.lin
    • http://xiixmcuin.linkpc.net/9208201208208205/The-Globalization-Paradigm-The-Impact-of-Globalization-on-Industry-Consolidation-through-Mergers-amp-Acquisitions-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/1200200203209205203/Vulnerability-and-Violence-The-Impact-of-Globalization-by-Peadar-Kirby.pdf
    • http://xiixmcuin.linkpc.net/8207205206200201/Cultures-and-Globalization-Heritage-Memory-and-Identity-The-Cultures-and-Globalization-Series-by-Yudhishthir-Raj-Isar.pdf
    • http://xiixmcuin.linkpc.net/1200204204204202206/Mergers-amp-Acquisitions-101-by-Scott-Tietz.pdf
    • http://xiixmcuin.linkpc.net/6209201206203207/Acquisitions-and-Mergers-The-Four-of-Wands-by-Lucius-Parhelion.pdf
    • http://xiixmcuin.linkpc.net/9202207206200201/The-Endgame-of-Globalization-by-Neil-Smith.pdf
    • http://xiixmcuin.linkpc.net/1200209205206206205/Globalization-of-Services-by-Yair-Aharoni.pdf
    • http://xiixmcuin.linkpc.net/1201200201200206201/Globalization-A-Short-History-by-J-rgen-Osterhammel.pdf
    • http://xiixmcuin.linkpc.net/1200204201209202201/Globalization-and-Welfare-A-Critical-Reader-by-Ritu-Vij.pdf
    • http://xiixmcuin.linkpc.net/6200202201207205/Globalization-the-State-and-Violence-by-Jonathan-Friedman.pdf
    • http://xiixmcuin.linkpc.net/2207205204204205/Europe-Globalization-and-the-Coming-Universal-Caliphate-by-Bat-Ye-39-or.pdf
    • http://xiixmcuin.linkpc.net/1200202209201206/Why-Your-World-Is-About-to-Get-a-Whole-Lot-Smaller-Oil-and-the-End-of-Globalization-by-Jeff-Rubin.pdf
    • http://xiixmcuin.linkpc.net/7209202204205201/Whatever-Else-Happened-to-the-Egyptians-From-the-Revolution-to-the-Age-of-Globalization-by-Galal-Amin.pdf
    • http://xiixmcuin.linkpc.net/6204207201202205/Handbook-of-Research-on-Stock-Market-Globalization-by-G-Poitras.pdf
    • http://xiixmcuin.linkpc.net/6207203205207208/Ricoeur-Hermeneutics-and-Globalization-by-Bengt-Kristensson-Uggla.pdf
    • http://xiixmcuin.linkpc.net/1206208200202200/Crazy-Like-Us-The-Globalization-of-the-American-Psyche-by-Ethan-Watters.pdf
    • http://xiixmcuin.linkpc.net/1201204209206204208/Ends-of-Globalization-Bringing-Society-Back-in-by-Don-Kalb.pdf
    • http://xiixmcuin.linkpc.net/5203201203205/An-Aesthetic-Education-in-the-Era-of-Globalization-by-Gayatri-Chakravorty-Spivak.pdf
    • http://xiixmcuin.linkpc.net/1206201209205205/Uncle-Sam-and-Us-Globalization-Neoconservatism-and-the-Canadian-State-by-Stephen-Clarkson.pdf
    • http://xiixmcuin.linkpc.net/5205209209206204/Capitalism-in-the-Age-of-Globalization-The-Management-of-Contemporary-Society-by-Samir-Amin.pdf