Malicious PDF — malware analysis report

Static analysis result for SHA-256 8127cd6f31dc9847…

MALICIOUS

PDF

25.8 KB Created: 2019-05-01 17:07:33 +01:00 Authoring application: mPDF 5.7
MD5: c584b357b28596fcbeacbe380eff697f SHA-1: d7cfe75307648d448f067248be8b85ae8b04b29e SHA-256: 8127cd6f31dc9847e330685ead369cd748d600c3025424bc30c7e921c5f539d9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates that the document is designed to host a large collection of links, likely for SEO manipulation or to direct users to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7204208206201203/Africa-Since-1940-The-Past-of-the-Present-by-Frederick-Cooper.pdf
    • http://xiixmcuin.linkpc.net/1201209200206202208/Coventry-Thursday-14-November-1940-by-Frederick-Taylor.pdf
    • http://xiixmcuin.linkpc.net/7204208207206206/The-Embrace-of-Unreason-France-1914-1940-by-Frederick-Brown.pdf
    • http://xiixmcuin.linkpc.net/7208203200205207/Afrique-de-La-Raison-Afrique-de-La-Foi-by-Meinrad-P-Hebga.pdf
    • http://xiixmcuin.linkpc.net/2202204204205202/Citizenship-Between-Empire-and-Nation-Remaking-France-and-French-Africa-1945-1960-by-Frederick-Cooper.pdf
    • http://xiixmcuin.linkpc.net/8201209200200209/Articles-on-Historians-of-Africa-Including-W-E-B-Du-Bois-Christopher-Ehret-Basil-Davidson-John-Henrik-Clarke-Yosef-Ben-Jochannan-Julian-Cobbing-Djibril-Tamsir-Niane-Runoko-Rashidi-Ivan-Van-Sertima-Ali-Mazrui-Frederick-Cooper-by-Hephaestus-Books.pdf
    • http://xiixmcuin.linkpc.net/6209209200207206/Facing-Frederick-The-Life-of-Frederick-Douglass-a-Monumental-American-Man-by-Tonya-Bolden.pdf
    • http://xiixmcuin.linkpc.net/8205201208205201/Narratives-Of-The-Life-Of-Frederick-Douglas-And-Walden-Color-Illustrated-Formatted-for-E-Readers-by-Frederick-Douglass.pdf
    • http://xiixmcuin.linkpc.net/1201205200209202208/The-Liber-Augustalis-Or-Constitutions-of-Melfi-Promulgated-by-the-Emperor-Frederick-II-for-the-Kingdom-of-Sicily-in-1231-by-Frederick-II-of-Hohenstaufen.pdf
    • http://xiixmcuin.linkpc.net/7200205205208203/Narrative-of-the-Life-of-Frederick-Douglass-An-American-Slave-Written-by-Himself-Bedford-Series-in-History-and-Culture-2nd-second-edition-Text-Only-by-Frederick-Douglass.pdf
    • http://xiixmcuin.linkpc.net/6201206200209207/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-Written-by-Himself-Critical-Edition-by-Frederick-Douglass.pdf
    • http://xiixmcuin.linkpc.net/7206202206209206/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-audio-book-Bel-publishing-by-Frederick-Douglass.pdf
    • http://xiixmcuin.linkpc.net/5203201203209205/Secret-Identity-Cooper-8-Cooper-Security-1-by-Paula-Graves.pdf
    • http://xiixmcuin.linkpc.net/2201201208201204/Secret-Intentions-Cooper-13-Cooper-Security-6-by-Paula-Graves.pdf
    • http://xiixmcuin.linkpc.net/3208203208207206/Secret-Keeper-Cooper-12-Cooper-Security-5-by-Paula-Graves.pdf
    • http://xiixmcuin.linkpc.net/5205200200206201/Narrative-of-the-Life-of-Frederick-Douglass-with-Cherokee-Removal-amp-Great-Awakening-by-Frederick-Douglass.pdf
    • http://xiixmcuin.linkpc.net/7208208200207203/Cooper-s-Novels-The-Last-of-the-Mohicans-by-James-Fenimore-Cooper.pdf
    • http://xiixmcuin.linkpc.net/5203208203200207/Je-Hais-Les-Trains-Depuis-Auschwitz-Poemes-by-Noureddine-Aba.pdf
    • http://xiixmcuin.linkpc.net/5203208202206200/A-toi-depuis-toujours-Tentation-br-silienne-t-1-by-Susan-Stephens.pdf
    • http://xiixmcuin.linkpc.net/5203208202200206/L-Edition-Francaise-Depuis-1945-by-Pascal-Fouch-.pdf