Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c2172da0dc416f5…

MALICIOUS

PDF

21.6 KB Created: 2019-05-02 17:53:13 +01:00 Authoring application: mPDF 5.7
MD5: 994166ee385e748a923950174ac984ce SHA-1: db9de58a6bc295fd6a7eda0b8b05019df12cc9ef SHA-256: 7c2172da0dc416f5ce84dda7c2fc66bc061ed5841bf843af2e508725e0315250
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, constituting a link farm designed to direct users to external content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of numerous external links, suggesting a potential SEO poisoning or traffic-driving scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://leakscaioiobook.4dq.com/9d0c8d0c9d0c2d0c0d0c3/Defending-Tierny-Gray-Wolf-Security-Texas-1-by-Glenna-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c9d0c2d0c0d0c2/COLE-Dragon-Security-1-by-Glenna-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c9d0c2d0c4d0c2/Hayden-Dragon-Security-5-by-Glenna-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/3d0c0d0c4d0c9d0c3d0c1/Frost-Security-The-Complete-5-Books-Series-by-Glenna-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c9d0c2d0c4d0c9/Dragon-Security-Boxed-Set-Dragon-Security-1-6-by-Glenna-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/9d0c8d0c8d0c7d0c0d0c6/Killian-The-Callahans-2-by-Glenna-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/2d0c0d0c9d0c2d0c8d0c0/Wolf-s-Destiny-Texas-Ranch-Wolf-Pack-Series-Complete-Books-1-6-by-Lynn-Nodima.pdf
    • http://leakscaioiobook.4dq.com/4d0c2d0c6d0c6d0c5d0c3/Mastering-Mari-Hot-Texas-Bosses-3-by-Lyla-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/5d0c0d0c9d0c9d0c7d0c4/Gray-Card-The-Department-of-Homeworld-Security-1-by-Cassandra-Chandler.pdf
    • http://leakscaioiobook.4dq.com/1d0c7d0c9d0c6d0c1d0c4/Winter-of-the-Wolf-The-Wild-Hunt-Legacy-2-by-Cherise-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/2d0c0d0c5d0c8d0c4d0c0/Winter-of-the-Wolf-The-Wild-Hunt-Legacy-2-by-Cherise-Sinclair.pdf
    • http://leakscaioiobook.4dq.com/2d0c1d0c9d0c2d0c1d0c1/Gray-Wolf-Island-by-Tracey-Neithercott.pdf
    • http://leakscaioiobook.4dq.com/9d0c5d0c1d0c5d0c3d0c5/Texas-Wolf-Sonderband-1-Der-Sohn-der-schwarzen-W-lfin-by-Glenn-Stirling.pdf
    • http://leakscaioiobook.4dq.com/9d0c0d0c6d0c7d0c0d0c3/Rescued-By-The-Wolf-Other-World-Series-4-by-Ramona-Gray.pdf
    • http://leakscaioiobook.4dq.com/5d0c7d0c6d0c4d0c2/The-Gray-Wolf-and-Other-Fantasy-Stories-by-George-MacDonald.pdf
    • http://leakscaioiobook.4dq.com/9d0c7d0c8d0c3d0c2d0c3/Wolf-in-Kunst-Und-Literatur-Der-Wolfsjunge-Rotkappchen-Kami-to-K-Shinry-Der-Mit-Dem-Wolf-Tanzt-Asena-Legende-Der-Wolfsmensch-Der-Wolf-Und-Die-Sieben-Jungen-Geisslein-Hase-Und-Wolf-Kapitolinische-Wolfin-Peter-Und-Der-Wolf-by-Source-Wikipedia.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c4d0c6d0c0d0c9/Security-Matters-Essays-On-Industrial-Security-by-Francis-Hamit.pdf
    • http://leakscaioiobook.4dq.com/3d0c2d0c8d0c2d0c6d0c5/Sharper-Security-A-Sovereign-Security-Company-Novel-by-Thomas-Sewell.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c9d0c5d0c0d0c0d0c1/Formal-Logical-Methods-for-System-Security-and-Correctness-Nato-Science-for-Peace-and-Security-by-Orna-Grumberg.pdf
    • http://leakscaioiobook.4dq.com/9d0c6d0c1d0c8d0c6d0c1/Der-IT-Security-Manager-Aktuelles-Praxiswissen-f-r-IT-Security-Manager-und-IT-Sicherheitsbeauftragte-in-Unternehmen-und-Beh-rden-by-Kersten.pdf