Malicious PDF — malware analysis report

Static analysis result for SHA-256 741c0c39baccaf77…

MALICIOUS

PDF

21.6 KB Created: 2019-05-07 04:36:20 +01:00 Authoring application: mPDF 5.7
MD5: 42f9789cd442967e7f0580ded8ea1bee SHA-1: 2f0face03609337355acd5c8cccd240ad8d5a8e5 SHA-256: 741c0c39baccaf779819da922559bc738fdda04eb62cb522f545723efadb82a5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to a multitude of potentially malicious websites. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2203200205208200/Leopold-and-Loeb-The-Crime-of-the-Century-by-Hal-Higdon.pdf
    • http://xiixmcuin.linkpc.net/8204202207201204/Crimes-of-the-Century-From-Leopold-and-Loeb-to-O-J-Simpson-by-Gilbert-Geis.pdf
    • http://xiixmcuin.linkpc.net/7204206209200203/The-Trial-of-Leopold-and-Loeb-A-Primary-Source-Account-by-Simone-Payment.pdf
    • http://xiixmcuin.linkpc.net/2202205204203209/The-Crime-of-the-Century-by-Kingsley-Amis.pdf
    • http://xiixmcuin.linkpc.net/9207200206207/The-Whiskey-Au-Go-Go-Massacre-Murder-Arson-and-the-Crime-of-the-Century-by-Geoff-Plunkett.pdf
    • http://xiixmcuin.linkpc.net/1206203208205/American-Lightning-Terror-Mystery-the-Birth-of-Hollywood-amp-the-Crime-of-the-Century-by-Howard-Blum.pdf
    • http://xiixmcuin.linkpc.net/1206208202200/The-Murder-of-the-Century-The-Gilded-Age-Crime-that-Scandalized-a-City-and-Sparked-the-Tabloid-Wars-by-Paul-Collins.pdf
    • http://xiixmcuin.linkpc.net/1206208209204/The-Rise-of-True-Crime-Twentieth-Century-Murder-and-American-Popular-Culture-by-Jean-Murley.pdf
    • http://xiixmcuin.linkpc.net/6209203204206205/Mannerism-in-Arabic-Poetry-A-Structural-Analysis-of-Selected-Texts-3rd-Century-Ah-9th-Century-Ad-5th-Century-Ah-11th-Century-Ad-by-Stefan-Sperl.pdf
    • http://xiixmcuin.linkpc.net/7204200201201209/To-an-ancient-people-The-autobiography-of-Dr-Leopold-Cohn-by-Leopold-Cohn.pdf
    • http://xiixmcuin.linkpc.net/2205200207201202/On-the-Run-from-Dogs-and-People-by-Hal-Higdon.pdf
    • http://xiixmcuin.linkpc.net/8200204200200207/Marathon-The-Ultimate-Training-Guide-by-Hal-Higdon.pdf
    • http://xiixmcuin.linkpc.net/5203206205201209/Crime-And-The-Law-The-Social-History-Of-Crime-In-Western-Europe-Since-1500-by-V-A-C-Gatrell.pdf
    • http://xiixmcuin.linkpc.net/3205207208200208/Marathon-The-Ultimate-Training-Guide-Advice-Plans-and-Programs-for-Half-and-Full-Marathons-by-Hal-Higdon.pdf
    • http://xiixmcuin.linkpc.net/7202200206209/You-Belong-to-Me-and-Other-True-Crime-Cases-Crime-Files-2-by-Ann-Rule.pdf
    • http://xiixmcuin.linkpc.net/3209208204200202/Numbering-the-Crime-Forensic-Mathematics-The-Crime-Scene-Club-Fact-and-Fiction-Book-11-by-Kenneth-McIntosh.pdf
    • http://xiixmcuin.linkpc.net/8200205204203/Spider-Man-Blue-by-Jeph-Loeb.pdf
    • http://xiixmcuin.linkpc.net/8206200209205/Batman-Hush-Vol-1-by-Jeph-Loeb.pdf
    • http://xiixmcuin.linkpc.net/4201204202204/Superman-for-All-Seasons-by-Jeph-Loeb.pdf
    • http://xiixmcuin.linkpc.net/7206208201209205/Moselle-by-Otto-Wolfgang-Loeb.pdf