Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b15d9ba3ae15272…

MALICIOUS

PDF

23.1 KB Created: 2019-04-30 17:52:01 +01:00 Authoring application: mPDF 5.7
MD5: 59905fb39cfb1e4e2ef5cb4e4d43f34b SHA-1: f421d6a40653b5107f4dbf2e6271016d188511fc SHA-256: 6b15d9ba3ae1527219c63b50ae2d18755e216fe75520be2cafa20f84706a0439
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly to manipulate search engine results or to serve as a distribution point for further malware. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4201207204202206/BRAN-MAK-MORN---The-Last-King-Men-of-the-Shadows-Kings-of-the-Night-A-Song-of-the-Race-Worms-of-the-Earth-The-Dark-Man-The-Lost-Race-The-Little-People-The-Children-of-the-Night-by-Robert-E-Howard.pdf
    • http://xiixmcuin.linkpc.net/1205208201207208/Bran-Mak-Morn-The-Last-King-by-Robert-E-Howard.pdf
    • http://xiixmcuin.linkpc.net/1201207207201209205/The-Race-Against-the-Stasi-The-Incredible-Story-of-Dieter-Wiedemann-The-Iron-Curtain-and-The-Greatest-Cycling-Race-on-Earth-by-Herbie-Sykes.pdf
    • http://xiixmcuin.linkpc.net/2201207206204202/Night-People-Things-We-Lost-in-the-Night-1-by-Larry-J-Dunlap.pdf
    • http://xiixmcuin.linkpc.net/4202201207207205/Race-the-Night-by-Kirsten-Hubbard.pdf
    • http://xiixmcuin.linkpc.net/5203201207209209/Beneath-a-Ruthless-Sun-A-True-Story-of-Violence-Race-and-Justice-Lost-and-Found-by-Gilbert-King.pdf
    • http://xiixmcuin.linkpc.net/1203202209202207/One-Empire-Night-Lost-Kings-MC-9-5-by-Autumn-Jones-Lake.pdf
    • http://xiixmcuin.linkpc.net/5208202203200208/Night-Shadows-Children-of-Nostradamus-2-by-Jeremy-Flagg.pdf
    • http://xiixmcuin.linkpc.net/3207207200209204/Night-s-Awakening-Dark-Kings-0-2-by-Donna-Grant.pdf
    • http://xiixmcuin.linkpc.net/1200209207209205/White-Mother-to-a-Dark-Race-Settler-Colonialism-Maternalism-and-the-Removal-of-Indigenous-Children-in-the-American-West-and-Australia-1880-1940-by-Margaret-D-Jacobs.pdf
    • http://xiixmcuin.linkpc.net/9206209203209201/Formula-5000-in-New-Zealand-amp-Australia-Race-by-Race-by-Wolfgang-Klopfer.pdf
    • http://xiixmcuin.linkpc.net/1206204207209203/Song-for-a-Summer-Night-by-Robert-Heidbreder.pdf
    • http://xiixmcuin.linkpc.net/2205206209206200/Race-of-the-Century-The-Heroic-True-Story-of-the-1908-New-York-to-Paris-Auto-Race-by-Julie-M-Fenster.pdf
    • http://xiixmcuin.linkpc.net/1202205202203206/What-We-Lost-in-the-Dark-What-We-Saw-at-Night-2-by-Jacquelyn-Mitchard.pdf
    • http://xiixmcuin.linkpc.net/3207209208206204/Night-s-Surrender-Children-of-the-Night-7-by-Amanda-Ashley.pdf
    • http://xiixmcuin.linkpc.net/4207206208200202/My-Song-A-Memoir-of-Art-Race-and-Defiance-by-Harry-Belafonte.pdf
    • http://xiixmcuin.linkpc.net/2209200202201200/The-Best-of-Robert-E-Howard-Crimson-Shadows-Volume-1-by-Robert-E-Howard.pdf
    • http://xiixmcuin.linkpc.net/6209205204203209/Kapp-To-Cape-Never-Look-Back-Race-to-the-End-of-the-Earth-by-Reza-Pakravan.pdf
    • http://xiixmcuin.linkpc.net/1200204209206/Earth-The-Book-A-Visitor-s-Guide-to-the-Human-Race-by-Jon-Stewart.pdf
    • http://xiixmcuin.linkpc.net/5208202207209207/Betrayal-against-the-white-race-The-white-race-has-been-betrayed-and-marked-for-genocide-by-Jerry-Henrie.pdf