Malicious PDF — malware analysis report

Static analysis result for SHA-256 5828f877cfbbbb5e…

MALICIOUS

PDF

28.7 KB Created: 2019-05-07 08:19:36 +01:00 Authoring application: mPDF 5.7
MD5: f77f4c875890fc0c1c29f60d8c1b4793 SHA-1: 09cb2408d68565a026d3128de3609f129a87de5d SHA-256: 5828f877cfbbbb5ebe1edb8f728fc011ecd891cad712d46e6b9b1e37b65fdf65
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF documents. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be a link farm designed to direct users to potentially malicious content hosted externally.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5208202207209207/Betrayal-against-the-white-race-The-white-race-has-been-betrayed-and-marked-for-genocide-by-Jerry-Henrie.pdf
    • http://xiixmcuin.linkpc.net/5208202207209202/Racism-from-a-White-Perspective-A-Book-All-People-to-Read-Especially-Non-Whites-It-Is-Time-We-Hear-from-a-Non-Liberal-the-Actual-Facts-by-Jerry-Henrie.pdf
    • http://xiixmcuin.linkpc.net/4201205200207202/White-Like-Me-Reflections-on-Race-from-a-Privileged-Son-by-Tim-Wise.pdf
    • http://xiixmcuin.linkpc.net/8205204205202207/White-by-Law-The-Legal-Construction-of-Race-by-Ian-F-Haney-Lopez.pdf
    • http://xiixmcuin.linkpc.net/4201205209207207/White-Essays-on-Race-and-Culture-by-Richard-Dyer.pdf
    • http://xiixmcuin.linkpc.net/2202204202202/Waking-Up-White-And-Finding-Myself-in-the-Story-of-Race-by-Debby-Irving.pdf
    • http://xiixmcuin.linkpc.net/5201204207200208/The-Black-Image-in-the-White-Mind-Media-and-Race-in-America-by-Robert-M-Entman.pdf
    • http://xiixmcuin.linkpc.net/6208209205202209/Black-Bodies-White-Gazes-The-Continuing-Significance-of-Race-by-George-Yancy.pdf
    • http://xiixmcuin.linkpc.net/4201205209208203/Between-Arab-and-White-Race-and-Ethnicity-in-the-Early-Syrian-American-Diaspora-by-Sarah-M-A-Gualtieri.pdf
    • http://xiixmcuin.linkpc.net/3205201206206201/The-Education-of-a-White-Parent-Wrestling-with-Race-and-Opportunity-in-the-Boston-Public-Schools-by-Susan-Naimark.pdf
    • http://xiixmcuin.linkpc.net/1201204204205200203/Swimming-with-Sharks-in-Dark-Water-Having-Race-and-Working-with-Grace-in-Corporate-White-America-by-Athene-Brinson.pdf
    • http://xiixmcuin.linkpc.net/5201205202202/For-Labor-Race-and-Liberty-George-Edwin-Taylor-His-Historic-Run-for-the-White-House-and-the-Making-of-Independent-Black-Politics-by-Bruce-L-Mouser.pdf
    • http://xiixmcuin.linkpc.net/1200201201202205208/Skin-Deep-Black-Women-amp-White-Women-Write-About-Race-by-Marita-Golden.pdf
    • http://xiixmcuin.linkpc.net/1200209207209205/White-Mother-to-a-Dark-Race-Settler-Colonialism-Maternalism-and-the-Removal-of-Indigenous-Children-in-the-American-West-and-Australia-1880-1940-by-Margaret-D-Jacobs.pdf
    • http://xiixmcuin.linkpc.net/9206209203209201/Formula-5000-in-New-Zealand-amp-Australia-Race-by-Race-by-Wolfgang-Klopfer.pdf
    • http://xiixmcuin.linkpc.net/2205206209206200/Race-of-the-Century-The-Heroic-True-Story-of-the-1908-New-York-to-Paris-Auto-Race-by-Julie-M-Fenster.pdf
    • http://xiixmcuin.linkpc.net/1201207207201209205/The-Race-Against-the-Stasi-The-Incredible-Story-of-Dieter-Wiedemann-The-Iron-Curtain-and-The-Greatest-Cycling-Race-on-Earth-by-Herbie-Sykes.pdf
    • http://xiixmcuin.linkpc.net/4201207204202206/BRAN-MAK-MORN---The-Last-King-Men-of-the-Shadows-Kings-of-the-Night-A-Song-of-the-Race-Worms-of-the-Earth-The-Dark-Man-The-Lost-Race-The-Little-People-The-Children-of-the-Night-by-Robert-E-Howard.pdf
    • http://xiixmcuin.linkpc.net/7207209209208209/The-Ignorant-Bystander-Britain-and-the-Rwandan-Genocide-of-1994-by-White-Dean-J.pdf
    • http://xiixmcuin.linkpc.net/2208200201205208/Emancipation-Betrayed-The-Hidden-History-of-Black-Organizing-and-White-Violence-in-Florida-from-Reconstruction-to-the-Bloody-Election-of-1920-by-Paul-Ortiz.pdf
    • http://xiixmcuin.linkpc.net/5201204207200208/The-Black-Image-in-the-White-Mind-Media-and-Race-in-Ame