Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d51e9f7f8363b9f…

MALICIOUS

PDF

19.7 KB Created: 2019-04-30 04:00:20 +01:00 Authoring application: mPDF 5.7
MD5: 4ce488976283212cb41790959ed908a5 SHA-1: c186e4af5282fef0b351b931dc2ba9509532f3ea SHA-256: 5d51e9f7f8363b9f877444b59dffacf34313dccb018b9d2cb240248d991716cf
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO manipulation tactic. While the document body contains some text, it is heavily obfuscated and appears to be a collection of URLs rather than coherent content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves leveraging these links, potentially to distribute further malware or engage in phishing, though no specific script execution was detected.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200209202201209206/Alles-in-der-Balance-und-doch-nichts-im-Einklang-Die-goldene-Mitte-finden-by-Martin-Bieri.pdf
    • http://xiixmcuin.linkpc.net/9208205201207201/Alles-ist-gut-Sechzehn-sehr-kurze-Geschichten-in-denen-gar-nichts-gut-ist-by-Diego-Bernardini.pdf
    • http://xiixmcuin.linkpc.net/1200209205209206207/Aus-Der-Mitte-in-Die-Mitte-by-Harald-Renkel.pdf
    • http://xiixmcuin.linkpc.net/8204200204202203/Creating-Balance-A-Self-Reflective-Book-to-Bring-More-Energy-Productivity-and-Balance-Into-Your-Life-by-Alene-Baronian.pdf
    • http://xiixmcuin.linkpc.net/2200200205203201/Balance-Off-Balance-1-by-Lucia-Franco.pdf
    • http://xiixmcuin.linkpc.net/6209205204200206/Kulturbanausen-Profit-und-Werte-in-Einklang-bringen-by-Christian-S-gtrop.pdf
    • http://xiixmcuin.linkpc.net/1200204202202208208/Der-Ausweg-aus-dem-Fliegenglas-wie-wir-Glauben-und-Vernunft-in-Einklang-bringen-k-nnen-by-Gert-Scobel.pdf
    • http://xiixmcuin.linkpc.net/2204200202201207/Janita-Und-Der-Goldene-Ring-by-Marilyn-Cram-Donahue.pdf
    • http://xiixmcuin.linkpc.net/1200206204205202207/Die-Legenden-der-Verfluchten-Die-goldene-Morgend-mmerung-by-Eden-Barrows.pdf
    • http://xiixmcuin.linkpc.net/1200209202201209203/Trouble-The-Last-Chance-by-Marc-Bieri.pdf
    • http://xiixmcuin.linkpc.net/1200207208206203209/Die-Goldene-Stadt-und-der-entgleiste-Bauzug-zweisprachiges-eBuch-9-by-Jutta-Mahlke.pdf
    • http://xiixmcuin.linkpc.net/1200209202200209207/Percy-Bysshe-Shelley-A-Biography-by-James-Bieri.pdf
    • http://xiixmcuin.linkpc.net/1200209202202205205/Computational-Geometry---Methods-Algorithms-and-Applications-by-Hanspeter-Bieri.pdf
    • http://xiixmcuin.linkpc.net/1200209202203201204/Distressed-Cities-and-Resilience-Social-Possibilities-and-Contexts-by-Anja-H-Bieri.pdf
    • http://xiixmcuin.linkpc.net/1201203207202206201/Tee-oder-Mokka-7-goldene-Verhaltenstipps-aus-der-Praxis-f-r-den-Umgang-mit-patriarchalischen-religi-sen-Migrantenfamilien-by-Benjamin-Bulgay.pdf
    • http://xiixmcuin.linkpc.net/1200209202203201200/Pierre-Teilhard-de-Chardin---Sinn-und-Ziel-der-Evolution-by-Peter-Gotthard-Bieri.pdf
    • http://xiixmcuin.linkpc.net/1200209206200209205/Aristoteles-Die-Mitte-in-seinem-Denken-by-Jan-van-der-Meulen.pdf
    • http://xiixmcuin.linkpc.net/1200209205209207205/Satan-s-Bible-for-the-Modern-World-by-MR-Mike-W-Mitte.pdf
    • http://xiixmcuin.linkpc.net/1200209202201200200/From-Blood-Diamonds-to-the-Kimberley-Process-How-NGOs-Cleaned-Up-the-Global-Diamond-Industry-by-Franziska-Bieri.pdf
    • http://xiixmcuin.linkpc.net/9207209208200205/Viel-L-rm-um-nichts-by-William-Shakespeare.pdf