Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e0231acb21c0fe0…

MALICIOUS

PDF

14.9 KB Created: 2019-05-01 19:05:05 +01:00 Authoring application: mPDF 5.7
MD5: 1fbe4055158b27789810158f46f89716 SHA-1: 285e3782036b763db2fe2ed2b2524613d67a7502 SHA-256: 5e0231acb21c0fe0a4affcab8fa323d6956ed5411ae675c525c4a021314171ae
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified as a link farm. While the document body is unreadable, the heuristic 'PDF_SEO_LINK_FARM' indicates a malicious intent to direct users to external resources. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9200

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4207201207202204/Breaking-Up-Point-by-Brian-McNamara.pdf
    • http://xiixmcuin.linkpc.net/4208200207209208/Breaking-Point-Turning-Point-2-by-N-R-Walker.pdf
    • http://xiixmcuin.linkpc.net/4205204208207209/Breaking-Point-Turning-Point-2-by-N-R-Walker.pdf
    • http://xiixmcuin.linkpc.net/4200202201206200/Breaking-Point-by-S-L-Armstrong.pdf
    • http://xiixmcuin.linkpc.net/3209205208208205/Breaking-Point-by-Alex-Flinn.pdf
    • http://xiixmcuin.linkpc.net/2204209208203202/Breaking-Point-by-Alex-Flinn.pdf
    • http://xiixmcuin.linkpc.net/4208208206203205/Breaking-Point-by-Frank-Smith.pdf
    • http://xiixmcuin.linkpc.net/2206203206207203/Breaking-Point-by-Roxanne-M-Dawson.pdf
    • http://xiixmcuin.linkpc.net/1208208201201200/The-Breaking-Point-by-Karen-Ball.pdf
    • http://xiixmcuin.linkpc.net/2207203204200209/The-Breaking-Point-by-Catrina-Wolfe.pdf
    • http://xiixmcuin.linkpc.net/4202204205/Honor-The-Breaking-Point-1-by-Jay-Crownover.pdf
    • http://xiixmcuin.linkpc.net/8205207208209201/Breaking-Point-Chapter-5-by-Rabi-Motoya.pdf
    • http://xiixmcuin.linkpc.net/8205207208208205/Breaking-Point-Chapter-2-by-Rabi-Motoya.pdf
    • http://xiixmcuin.linkpc.net/8205207208209200/Breaking-Point-Chapter-1-by-Rabi-Motoya.pdf
    • http://xiixmcuin.linkpc.net/8205207208208207/Breaking-Point-Chapter-6-by-Rabi-Motoya.pdf
    • http://xiixmcuin.linkpc.net/3200208208205208/The-Pursuit-of-Loneliness-American-Culture-at-the-Breaking-Point-by-Philip-Slater.pdf
    • http://xiixmcuin.linkpc.net/5208205206209203/Breaking-the-No-Barrier-How-to-Leverage-the-Power-of-Persistence-and-Impatience-by-Brian-Douglas-McIntosh.pdf
    • http://xiixmcuin.linkpc.net/7207207204208208/Selected-Papers---Oeuvres-Scientifiques-I-Topology-and-Fixed-Point-Theorems-Topologie-Et-Theoreme-Du-Point-Fixe-Topologie-Et-Theoreme-Du-Point-Fixe-by-Jean-Leray.pdf
    • http://xiixmcuin.linkpc.net/1205200202209207/Breaking-the-Rules-The-Breaking-Series-1-by-Nicole-Sturgill.pdf
    • http://xiixmcuin.linkpc.net/1207202202209206/Reckless-Point-Cross-Point-Village-1-by-Cora-Brent.pdf