Malicious PDF — malware analysis report

Static analysis result for SHA-256 8401578b15a26d87…

MALICIOUS

PDF

15.9 KB Created: 2019-04-30 06:41:41 +01:00 Authoring application: mPDF 5.7
MD5: c78ec24bfea5097215852105fc007c05 SHA-1: 9d3cc75457058bfe7dd076b4fd358ebf14be696b SHA-256: 8401578b15a26d871cea822f2b5f6a715d06db7ea9579130faed43bfa4a5cf32
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, many of which are disguised as book titles, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves tricking users into clicking these links, likely leading to further malicious content or phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2209201208204207/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/5204204200206205/The-Great-Gatsby-by-FITZGERALD-F-SCOTT.pdf
    • http://xiixmcuin.linkpc.net/8205202208207209/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/2208209200207206/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/7200207208206/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/7204200209201205/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/4209202202208200/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/1200205205204201202/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/7207201202200200/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/6206204200208203/The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/5204204200200208/F-Scott-Fitzgerald-s-the-Great-Gatsby-by-Harold-Bloom.pdf
    • http://xiixmcuin.linkpc.net/5204203207209200/Trimalchio-An-Early-Version-of-The-Great-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/6202200206201201/The-Last-Gatsby-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/4203208202201205/Gatsby-Girls-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/5204204201203204/The-Great-Gatsby-F-Scott-Fitzgerald-Anne-Crow-by-Anne-Crow.pdf
    • http://xiixmcuin.linkpc.net/5204203209201201/Before-Gatsby-The-First-Twenty-Six-Stories-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/5204203209200202/Cliffs-Notes-on-Fitzgerald-s-the-Great-Gatsby-by-Kate-Maurer.pdf
    • http://xiixmcuin.linkpc.net/7207202200201208/The-Curious-Case-of-Benjamin-Button-Brad-Pitt---Illustrated-with-movie-pictures---Francis-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/8202204208207208/F-Scott-Fitzgerald-Four-Pack---Benjamin-Button-This-Side-of-Paradise-The-Beautiful-and-Damned-The-Diamond-as-big-as-The-Ritz-Illustrated-by-Norman-Rockwell-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/5204204201203208/The-Great-Gatsby-What-If-Gatsby-Was-a-Women-by-Mary-J-Greene.pdf