Malicious PDF — malware analysis report

Static analysis result for SHA-256 68434d87844e80e8…

MALICIOUS

PDF

25.1 KB Created: 2020-03-19 06:52:53 +00:00 Authoring application: mPDF 5.7
MD5: 0bd6d0bfb350364b06dc330d1af11cbf SHA-1: 429ef19be3c115d9ff649b7cccaca1d1602f6e58 SHA-256: 68434d87844e80e82fb1cba383f5a342993fb090a4dea50c53c530a5e28bdebf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files hosted on a dynamic DNS domain, identified by the PDF_SEO_LINK_FARM heuristic. This suggests a tactic to manipulate search engine results or distribute potentially malicious content through a link farm. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://reiteaspdf.dyndns.co.za/79fa19fa09fa39fa79fa4/Power-Speak-Engage-Inspire-and-Stimulate-Your-Audience-by-Dorothy-Leeds.pdf
    • http://reiteaspdf.dyndns.co.za/79fa19fa79fa09fa19fa6/Brand-Romance-Using-the-Power-of-High-Design-to-Build-a-Lifelong-Relationship-with-Your-Audience-by-Yasushi-Kusume.pdf
    • http://reiteaspdf.dyndns.co.za/19fa19fa09fa19fa89fa29fa7/Voices-of-Power-World-Leaders-Speak-by-Henry-Bienen.pdf
    • http://reiteaspdf.dyndns.co.za/79fa79fa39fa69fa89fa3/Secrets-of-Dynamic-Communications-Prepare-with-Focus-Deliver-with-Clarity-Speak-with-Power-by-Ken-Davis.pdf
    • http://reiteaspdf.dyndns.co.za/69fa09fa99fa49fa09fa6/Change-Your-Words-Change-Your-Life-Understanding-the-Power-of-Every-Word-You-Speak-by-Joyce-Meyer.pdf
    • http://reiteaspdf.dyndns.co.za/49fa39fa89fa29fa29fa9/Speak-English-Like-an-American-You-Already-Speak-English---Now-Speak-It-Even-Better-by-Amy-Gillett.pdf
    • http://reiteaspdf.dyndns.co.za/49fa99fa59fa19fa39fa5/Through-a-Dog-s-Ear-Using-Sound-to-Improve-the-Health-amp-Behavior-of-Your-Canine-Companion-by-Joshua-Leeds.pdf
    • http://reiteaspdf.dyndns.co.za/99fa89fa39fa99fa79fa3/Well-Suited-A-History-Of-The-Leeds-Clothing-Industry-1850-1990-by-Katrina-Honeyman.pdf
    • http://reiteaspdf.dyndns.co.za/89fa99fa19fa69fa29fa0/ENGLISCH-LERNEN---I-SPEAK-ENGLISCH-Englisch-lernen-Power-Wortschatz---ber-1000-kraftvolle-W-rter-f-r-ein-starkes-Leben-by-ENGLISCH-LERNEN.pdf
    • http://reiteaspdf.dyndns.co.za/19fa89fa09fa89fa29fa5/Alaska-and-Back-With-Dave-and-Dorothy-by-Dorothy-May-Mercer.pdf
    • http://reiteaspdf.dyndns.co.za/49fa09fa09fa49fa19fa4/Smart-Baby-Clever-Child-Brain-Building-Games-Activites-and-Ideas-to-Stimulate-Your-Baby-s-Mind-by-Valentine-Dmitriev.pdf
    • http://reiteaspdf.dyndns.co.za/19fa09fa69fa59fa49fa9/Speak-of-the-Devil-Speak-of-the-Devil-1-by-Shawna-Romkey.pdf
    • http://reiteaspdf.dyndns.co.za/39fa59fa19fa29fa59fa8/An-Audience-of-Chairs-by-Joan-Clark.pdf
    • http://reiteaspdf.dyndns.co.za/19fa29fa49fa89fa09fa3/Mannequins-in-the-Audience-by-David-J-Rollins.pdf
    • http://reiteaspdf.dyndns.co.za/19fa69fa29fa89fa99fa2/Mannequins-in-the-Audience-by-David-J-Rollins.pdf
    • http://reiteaspdf.dyndns.co.za/89fa89fa59fa2/Legion-The-Many-Lives-of-Stephen-Leeds-Legion-1-3-by-Brandon-Sanderson.pdf
    • http://reiteaspdf.dyndns.co.za/49fa59fa59fa29fa99fa2/Dorothy-Must-Die-Dorothy-Must-Die-1-by-Danielle-Paige.pdf
    • http://reiteaspdf.dyndns.co.za/79fa99fa59fa89fa5/Dorothy-Must-Die-Dorothy-Must-Die-1-by-Danielle-Paige.pdf
    • http://reiteaspdf.dyndns.co.za/19fa19fa79fa39fa59fa79fa0/The-Power-of-Praying-A-3-In-1-Collection-The-Power-of-a-Praying-Wife-The-Power-of-a-Praying-Parent-The-Power-of-a-Praying-Woman-by-Stormie-Omartian.pdf
    • http://reiteaspdf.dyndns.co.za/19fa19fa69fa29fa29fa19fa6/Better-Beginnings-How-To-Capture-Your-Audience-In-30-Seconds-by-Carmen-Taran.pdf