Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b1afe4afd4d33bf…

MALICIOUS

PDF

19.4 KB Created: 2019-05-07 04:20:46 +01:00 Authoring application: mPDF 5.7
MD5: 5402f640ad8bf2e6b20e058776af144f SHA-1: 5e61d61af778d214e84a22e0f36061a4b62ae784 SHA-256: 6b1afe4afd4d33bf05d46d203ca888ffd0fe77215208770f317d4c465b931ca9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates this is a technique to generate traffic or potentially distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4202201206207201/True-Stories-of-Crime-and-Murder-True-Crime-1-by-Claire-Conally.pdf
    • http://xiixmcuin.linkpc.net/2203209200203203/Murder-at-40-Below-True-Crime-Stories-from-Alaska-by-Tom-Brennan.pdf
    • http://xiixmcuin.linkpc.net/7209209209205203/Masters-of-True-Crime-Chilling-Stories-of-Murder-and-the-Macabre-by-R-Barri-Flowers.pdf
    • http://xiixmcuin.linkpc.net/3203204208207202/2014-Serial-Killers-True-Crime-Anthology-Annual-True-Crime-Anthology-1-by-Peter-Vronsky.pdf
    • http://xiixmcuin.linkpc.net/7202200206209/You-Belong-to-Me-and-Other-True-Crime-Cases-Crime-Files-2-by-Ann-Rule.pdf
    • http://xiixmcuin.linkpc.net/8209201205206201/Murder-Most-Russian-True-Crime-and-Punishment-in-Late-Imperial-Russia-by-Louise-McReynolds.pdf
    • http://xiixmcuin.linkpc.net/1206208209204/The-Rise-of-True-Crime-Twentieth-Century-Murder-and-American-Popular-Culture-by-Jean-Murley.pdf
    • http://xiixmcuin.linkpc.net/5202202204208200/From-Midnight-to-Guntown-True-Crime-Stories-from-a-Federal-Prosecutor-in-Mississippi-by-John-Hailman.pdf
    • http://xiixmcuin.linkpc.net/4207207204205207/The-Old-Man-and-the-Gun-And-Other-Tales-of-True-Crime-by-David-Grann.pdf
    • http://xiixmcuin.linkpc.net/2203208208200201/In-the-Name-of-Love-and-Other-True-Cases-Crime-Files-4-by-Ann-Rule.pdf
    • http://xiixmcuin.linkpc.net/4202209206202203/Stories-of-Murder-Crime-amp-Mayhem-Vol-2-3-Suspenseful-Stories-by-Charles-Swope.pdf
    • http://xiixmcuin.linkpc.net/1207200207207/May-God-Have-Mercy-A-True-Story-of-Crime-and-Punishment-by-John-C-Tucker.pdf
    • http://xiixmcuin.linkpc.net/6209208206201/A-Rage-to-Kill-and-Other-True-Cases-Crime-Files-6-by-Ann-Rule.pdf
    • http://xiixmcuin.linkpc.net/2206208209206/A-Rose-for-Her-Grave-and-Other-True-Cases-Crime-Files-1-by-Ann-Rule.pdf
    • http://xiixmcuin.linkpc.net/2200207209205203/The-Irish-Game-A-True-Story-of-Crime-and-Art-by-Matthew-Hart.pdf
    • http://xiixmcuin.linkpc.net/4203209201206204/The-Curbchek-Collection-A-Trilogy-of-True-Crime-by-Zach-Fortier.pdf
    • http://xiixmcuin.linkpc.net/4204202205203201/The-Hunting-Accident-A-True-Story-of-Crime-and-Poetry-by-David-L-Carlson.pdf
    • http://xiixmcuin.linkpc.net/6206201208/The-57-Bus-A-True-Story-of-Two-Teenagers-and-the-Crime-That-Changed-Their-Lives-by-Dashka-Slater.pdf
    • http://xiixmcuin.linkpc.net/3204203201206200/Death-of-Innocence-The-True-Story-of-an-Unspeakable-Teenage-Crime-by-Peter-Meyer.pdf
    • http://xiixmcuin.linkpc.net/3203204208206204/2015-Serial-Killers-True-Crime-Anthology-Volume-2-by-Peter-Vronsky.pdf