Malicious PDF — malware analysis report

Static analysis result for SHA-256 6940f8eb66f34724…

MALICIOUS

PDF

19.2 KB Created: 2019-05-02 02:08:20 +01:00 Authoring application: mPDF 5.7
MD5: 9ece5e5d07d3b2a78e53c0c179aa02cc SHA-1: 735bfadae608aed8a22769e144ecd5dc383903ef SHA-256: 6940f8eb66f34724e122ee69597705f711746e1e6fbe130634e914d483efdbad
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier as malicious. It contains a large number of embedded external links, identified as a PDF link farm, which is a technique often used for SEO manipulation or to distribute further malicious content. While the specific intent of the links is unclear due to benign reputation labels, the sheer volume and the heuristic firing suggest a malicious purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://leakscaioiobook.4dq.com/1d0c1d0c0d0c4d0c2d0c8d0c6/The-Beautiful-and-Damned-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/4d0c4d0c5d0c7d0c0d0c2/The-Beautiful-and-Damned-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/8d0c4d0c1d0c7d0c9d0c1/The-Beautiful-and-Damned-Annotated-20th-Century-Fiction-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/1d0c9d0c1d0c1d0c9d0c5/The-Complete-Works-of-F-Scott-Fitzgerald-Classics-Book-8-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/7d0c4d0c8d0c7d0c5d0c7/F-Scott-Fitzgerald-Short-Stories-1921-to-1940-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/5d0c2d0c5d0c2d0c5d0c1/This-Side-of-Paradise-Is-the-Debut-Novel-by-F-Scott-Fitzgerald-original-Classic-By-Rupert-Brooke-3-August-1887---23-April-1915-Was-an-English-Poet-and-by-Oscar-Wilde-16-October-1854---30-November-1900-Was-an-Irish-Playwright-Novelist-Essayist-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/8d0c1d0c6d0c9d0c7d0c8/The-Best-Early-Stories-of-F-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/1d0c9d0c2d0c5d0c5d0c0/F-Scott-Fitzgerald-Tales-of-the-Jazz-Age-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/9d0c6d0c7d0c1d0c9/The-Complete-Works-of-F-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/1d0c0d0c5d0c1d0c6d0c3d0c6/Fool-for-Love-F-Scott-Fitzgerald-by-Scott-Donaldson.pdf
    • http://leakscaioiobook.4dq.com/8d0c6d0c2d0c4d0c2/Trimalchio-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/7d0c6d0c3d0c5d0c5d0c3/One-Interne-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c7d0c4d0c6d0c1/This-Side-of-Paradise-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/6d0c7d0c5d0c6d0c9d0c9/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/5d0c9d0c3d0c7d0c0d0c6/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c8d0c4d0c5d0c5d0c3/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/8d0c5d0c2d0c8d0c7d0c9/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/5d0c4d0c4d0c0d0c0d0c4/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c4d0c7d0c7d0c5d0c3/The-Camel-s-Back-by-F-Scott-Fitzgerald.pdf
    • http://leakscaioiobook.4dq.com/5d0c5d0c9d0c8d0c5d0c4/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf