Malicious PDF — malware analysis report

Static analysis result for SHA-256 55c6b4966b9cac0d…

MALICIOUS

PDF

25.5 KB Created: 2019-04-30 03:36:07 +01:00 Authoring application: mPDF 5.7
MD5: 9e96b99ae068731e4a0f11143b0a25d1 SHA-1: 6d96bf4d44b94fe1e7587130678d7b5c653da97b SHA-256: 55c6b4966b9cac0d51cc225cb1ccbe86dca99589c82df0f1a5fb95f9242f8e6a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the use of a dynamic DNS hostname suggest a potential for malicious redirection or SEO abuse. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9910

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8206205202201206/No-Free-Lunch-Food-amp-Revolution-in-Cuba-Today-by-Medea-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/8206205202201204/Cuba-Talking-about-Revolution-Conversations-with-Juan-Antonio-Blanco-New-Ed-1996-by-Medea-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/4207201206207206/Lunch-Wars-How-to-Start-a-School-Food-Revolution-and-Win-the-Battle-for-Our-Children-s-Health-by-Amy-Kalafa.pdf
    • http://xiixmcuin.linkpc.net/8206205200209206/Kingdom-of-the-Unjust-Behind-the-U-S-Saudi-Connection-by-Medea-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/8206205200205202/Drone-Warfare-Killing-By-Remote-Control-by-Medea-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/8206205202206201/The-Peace-Corps-and-More-175-Ways-to-Work-Study-and-Travel-at-Home-amp-Abroad-by-Medea-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/1208209203202200/Free-for-All-Fixing-School-Food-in-America-California-Studies-in-Food-and-Culture-28-by-Janet-Poppendieck.pdf
    • http://xiixmcuin.linkpc.net/4207207206201204/Pichon-Race-and-Revolution-in-Castro-s-Cuba-A-Memoir-by-Carlos-Moore.pdf
    • http://xiixmcuin.linkpc.net/3205205209204202/The-Food-Babe-Way-Break-Free-from-the-Hidden-Toxins-in-Your-Food-and-Lose-Weight-Look-Years-Younger-and-Get-Healthy-in-Just-21-Days-by-Vani-Hari.pdf
    • http://xiixmcuin.linkpc.net/3202204208207208/No-Such-Thing-as-a-Free-Lunch-A-Brandy-Alexander-Mystery-3-by-Shelly-Fredman.pdf
    • http://xiixmcuin.linkpc.net/3201200201207203/Vegan-Lunch-Box-130-Amazing-Animal-free-Lunches-Kids-and-Grown-ups-Will-Love-by-Jennifer-McCann.pdf
    • http://xiixmcuin.linkpc.net/8206205201206200/The-Medea-of-Euripides-and-the-Medea-of-Grillparzer-by-Chiles-Clifton-Ferrell.pdf
    • http://xiixmcuin.linkpc.net/1201202202207201208/Sayuri-s-Raw-Food-Cafe-Easy-Delicious-Healthy-Raw-vegan-vegetarian-gluten-free-diet-and-dessert-to-nourish-your-body-and-heart-as-well-as-healing-and-Sayuri-s-Raw-Food-cookbook-Book-1-by-Sayuri-Tanaka.pdf
    • http://xiixmcuin.linkpc.net/4207201204202204/100-Million-Years-of-Food-What-Our-Ancestors-Ate-and-Why-It-Matters-Today-by-Stephen-Le.pdf
    • http://xiixmcuin.linkpc.net/9201205202208205/Free-for-All-Defending-Liberty-in-America-Today-by-Wendy-Kaminer.pdf
    • http://xiixmcuin.linkpc.net/2207202207206200/Free-Food-for-Millionaires-by-Min-Jin-Lee.pdf
    • http://xiixmcuin.linkpc.net/1200205205208204/A-Free-Man-of-Color-Benjamin-January-1-by-Barbara-Hambly.pdf
    • http://xiixmcuin.linkpc.net/5207203207201203/The-Thing-About-Jellyfish---FREE-PREVIEW-EDITION-The-First-11-Chapters-by-Ali-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/2207207200206208/Food-Free-at-Last-How-I-Learned-to-Eat-Air-by-Dr-Robert-Jones-MD-PhD-DDS-ODD.pdf
    • http://xiixmcuin.linkpc.net/4204207200204202/The-Comic-Book-Story-of-Beer-The-World-s-Favorite-Beverage-from-7000-BC-to-Today-s-Craft-Brewing-Revolution-by-Jonathan-Hennessey.pdf
    • http://xiixmcuin.linkpc.net