Malicious PDF — malware analysis report

Static analysis result for SHA-256 77bfa891b17a85c2…

MALICIOUS

PDF

22.5 KB Created: 2019-04-30 02:24:24 +01:00 Authoring application: mPDF 5.7
MD5: 826a409e6fcf2e191c3590e3624a5dc9 SHA-1: 65a22badb89ee8255729fbe7fb8cd59bd9fd3c50 SHA-256: 77bfa891b17a85c2ff48f08ea4264cda081c194122d95cdd33954739dcd01512
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to host malicious content. No scripts were extracted, and the document body was heavily obfuscated, preventing further analysis of its specific purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200203201202206/The-Resilient-Enterprise-Overcoming-Vulnerability-for-Competitive-Advantage-by-Yossi-Sheffi.pdf
    • http://xiixmcuin.linkpc.net/6203203204204209/Leadership-for-Competitive-Advantage-by-Nick-Georgiades.pdf
    • http://xiixmcuin.linkpc.net/7201201200208204/Logistic-Management-A-Competitive-Advantage-for-the-New-Millennium-by-Kunal-Sharma.pdf
    • http://xiixmcuin.linkpc.net/8203202207200207/Elite-Minds-Creating-the-Competitive-Advantage-by-Stan-Beecham.pdf
    • http://xiixmcuin.linkpc.net/3202209203205202/Competitive-Advantage-Creating-and-Sustaining-Superior-Performance-by-Michael-E-Porter.pdf
    • http://xiixmcuin.linkpc.net/3203200203203200/Beyond-Performance-How-Great-Organizations-Build-Ultimate-Competitive-Advantage-by-Scott-Keller.pdf
    • http://xiixmcuin.linkpc.net/5208201206204202/Leveraging-Knowledge-Based-Assets-The-New-Value-Equation-to-Create-Competitive-Advantage-by-Marius-Ungerer.pdf
    • http://xiixmcuin.linkpc.net/9204207207208207/Business-Modeling-for-Life-Science-and-Biotech-Companies-Creating-Value-and-Competitive-Advantage-with-the-Milestone-Bridge-by-Alberto-Onetti.pdf
    • http://xiixmcuin.linkpc.net/1200201205207207/The-Design-of-Business-Why-Design-Thinking-is-the-Next-Competitive-Advantage-by-Roger-L-Martin.pdf
    • http://xiixmcuin.linkpc.net/1200200200201203208/Hearing-the-Voice-of-the-Market-Competitive-Advantage-Through-Creative-Use-of-Market-Information-by-Vincent-Barabba.pdf
    • http://xiixmcuin.linkpc.net/4202202200208207/The-Lean-Strategy-Using-Lean-to-Create-Competitive-Advantage-Unleash-Innovation-and-Deliver-Sustainable-Growth-by-Michael-Ball-.pdf
    • http://xiixmcuin.linkpc.net/9203207201206202/Effective-Use-of-Microsoft-Enterprise-Library-Building-Blocks-for-Creating-Enterprise-Applications-and-Services-by-Len-Fenster.pdf
    • http://xiixmcuin.linkpc.net/1201201204209201202/Mapping-Vulnerability-by-Greg-Bankoff.pdf
    • http://xiixmcuin.linkpc.net/1200200203209205203/Vulnerability-and-Violence-The-Impact-of-Globalization-by-Peadar-Kirby.pdf
    • http://xiixmcuin.linkpc.net/4209205203208204/Resilient-Heart-by-Annabeth-Albert.pdf
    • http://xiixmcuin.linkpc.net/7204203209204/Everything-Changes-Resilient-Love-1-by-Melanie-Hansen.pdf
    • http://xiixmcuin.linkpc.net/6200203201202/The-Power-of-Vulnerability-Teachings-of-Authenticity-Connections-and-Courage-by-Bren-Brown.pdf
    • http://xiixmcuin.linkpc.net/1204209206208203/Yossi-Yasser-amp-Other-Soldiers-by-Jon-Sebba.pdf
    • http://xiixmcuin.linkpc.net/3202208208203201/The-Amazing-Snowman-Duel-by-Yossi-Lapid.pdf
    • http://xiixmcuin.linkpc.net/9204209204201200/The-Snowman-Paul-Series-by-Yossi-Lapid.pdf