Malicious PDF — malware analysis report

Static analysis result for SHA-256 585e04b850bc1876…

MALICIOUS

PDF

23.0 KB Created: 2019-04-30 04:18:11 +01:00 Authoring application: mPDF 5.7
MD5: f0bd63841caf25fe08a1575bc52172d5 SHA-1: e18f0086a1dd37acab775628bc0de99b1186dd4a SHA-256: 585e04b850bc18764e1d668527d9718004a02553a65988c57d4bfea772fd8c77
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary heuristic identified a link farm of 28 external PDFs hosted on a dynamic DNS domain, suggesting a distribution or redirection mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7205203209202205/The-Wall-Street-Journal-Guide-to-Information-Graphics-The-Dos-and-Don-ts-of-Presenting-Data-Facts-and-Figures-by-Dona-M-Wong.pdf
    • http://xiixmcuin.linkpc.net/3203200202206209/Bull-by-the-Horns-Fighting-to-Save-Main-Street-from-Wall-Street-and-Wall-Street-from-Itself-by-Sheila-Bair.pdf
    • http://xiixmcuin.linkpc.net/5200206206/Black-Edge-Inside-Information-Dirty-Money-and-the-Quest-to-Bring-Down-the-Most-Wanted-Man-on-Wall-Street-by-Sheelah-Kolhatkar.pdf
    • http://xiixmcuin.linkpc.net/3206206202207205/Rediscovering-Values-On-Wall-Street-Main-Street-and-Your-Street-A-Moral-Compass-for-the-New-Economy-by-Jim-Wallis.pdf
    • http://xiixmcuin.linkpc.net/9204206207208209/Guide-to-Intelligent-Data-Analysis-How-to-Intelligently-Make-Sense-of-Real-Data-by-Michael-Berthold.pdf
    • http://xiixmcuin.linkpc.net/1208209207202206/The-Great-American-Stickup-How-Reagan-Republicans-and-Clinton-Democrats-Enriched-Wall-Street-While-Mugging-Main-Street-by-Robert-Scheer.pdf
    • http://xiixmcuin.linkpc.net/1200202202203205203/Manufacturing-Information-and-Data-Systems-by-Franjo-Cecelja.pdf
    • http://xiixmcuin.linkpc.net/1200208201205203202/The-Way-We-Were-Book-Images-Anecdotes-Technical-Information-and-History-Data-by-George-Forss.pdf
    • http://xiixmcuin.linkpc.net/1201203205206205207/Disinformation-Book-of-Lists-Subversive-Facts-and-Hidden-Information-in-Rapid-Fire-Format-by-Russ-Kick.pdf
    • http://xiixmcuin.linkpc.net/9205205205201205/The-End-of-Wall-Street-by-Roger-Lowenstein.pdf
    • http://xiixmcuin.linkpc.net/3209204208/King-of-Wall-Street-by-Louise-Bay.pdf
    • http://xiixmcuin.linkpc.net/1201202200202200205/Big-Data-Little-Data-No-Data-Scholarship-in-the-Networked-World-by-Christine-L-Borgman.pdf
    • http://xiixmcuin.linkpc.net/1208209203203201/This-Changes-Everything-Occupy-Wall-Street-and-the-99-Movement-by-Sarah-van-Gelder.pdf
    • http://xiixmcuin.linkpc.net/1200205209205204207/The-86-Biggest-Lies-on-Wall-Street-by-John-R-Talbott.pdf
    • http://xiixmcuin.linkpc.net/8209202209/Hard-Sell-21-Wall-Street-2-by-Lauren-Layne.pdf
    • http://xiixmcuin.linkpc.net/9204200202209204/Wall-Street-and-the-Rise-of-Hitler-by-Antony-C-Sutton.pdf
    • http://xiixmcuin.linkpc.net/2204205203205201/Confidence-Men-Wall-Street-Washington-and-the-Education-of-a-President-by-Ron-Suskind.pdf
    • http://xiixmcuin.linkpc.net/2207201205201202/Bartleby-The-Scrivener-A-Story-of-Wall-Street-by-Herman-Melville.pdf
    • http://xiixmcuin.linkpc.net/4207208201209203/FIASCO-Blood-in-the-Water-on-Wall-Street-by-Frank-Partnoy.pdf
    • http://xiixmcuin.linkpc.net/4201200202203200/Where-Are-the-Customers-Yachts-Or-a-Good-Hard-Look-at-Wall-Street-by-Fred-Schwed-Jr-.pdf