Malicious PDF — malware analysis report

Static analysis result for SHA-256 956c1125ae1a1f1c…

MALICIOUS

PDF

29.1 KB Created: 2019-04-30 18:58:39 +01:00 Authoring application: mPDF 5.7
MD5: 118b004196ed77c0631bddf26ac0f1ae SHA-1: dfcaea4cae650110198016214c22f6760d14eaf4 SHA-256: 956c1125ae1a1f1c8f7a2c71fee29b928591a5e6a5ccf3ae1ada2dc2651da95d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links are presented in a way that suggests they lead to book downloads, but their sheer volume and the use of a dynamic DNS hostname indicate a potential attempt to distribute malware or lead users to malicious websites. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1209202201205208/Kennedy-s-Wars-Berlin-Cuba-Laos-and-Vietnam-by-Lawrence-Freedman.pdf
    • http://xiixmcuin.linkpc.net/6202201208207200/Vietnam-In-Laos-Hanoi-s-Model-For-Kampuchea-by-Martin-Stuart-Fox.pdf
    • http://xiixmcuin.linkpc.net/3208203203208202/Thailand-Vietnam-Laos-amp-Cambodia-Travel-Atlas-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/3205200209204201/Revolution-Reform-and-Regionalism-in-Southeast-Asia-Cambodia-Laos-and-Vietnam-by-Ronald-Bruce-St-John.pdf
    • http://xiixmcuin.linkpc.net/1200205203204202205/Battle-Captain-Cold-War-Campaigning-With-The-U-S-Army-In-Vietnam-Cambodia-amp-Laos-1967-1971-by-Sewall-Menzel.pdf
    • http://xiixmcuin.linkpc.net/6202202200203209/Panoramic-Views-of-Asia-Kampuchea-Laos-Vietnam-Java-Borneo-Hong-Kong-amp-India-Let-Loose-Again-Book-16-by-John-Armstrong.pdf
    • http://xiixmcuin.linkpc.net/6202201209208203/Asia-the-beautiful-cookbook-authentic-recipes-from-Japan-Korea-China-the-Philippines-Thailand-Laos-and-Kampuchea-Vietnam-Singapore-and-Malaysia-India-Burma-Indonesia-and-Sri-Lanka-by-Jacki-Passmore.pdf
    • http://xiixmcuin.linkpc.net/6208207200204206/Tragic-Mountains-The-Hmong-the-Americans-and-the-Secret-Wars-for-Laos-1942-1992-by-Jane-Hamilton-Merritt.pdf
    • http://xiixmcuin.linkpc.net/1206200208207200/A-Choice-of-Enemies-America-Confronts-the-Middle-East-by-Lawrence-Freedman.pdf
    • http://xiixmcuin.linkpc.net/6203202205201200/History-of-Berlin-Ich-Bin-Ein-Berliner-Wannsee-Conference-Berlin-Wall-West-Berlin-East-Berlin-Nikolaiviertel-Berlin-Blockade-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/1208205202206/American-Tragedy-Kennedy-Johnson-and-the-Origins-of-the-Vietnam-War-by-David-E-Kaiser.pdf
    • http://xiixmcuin.linkpc.net/1200203204208204206/Bahnhof-in-Berlin-Bahnhof-Berlin-Zoologischer-Garten-Bahnhof-Berlin-Lichtenberg-Berlin-Hauptbahnhof-Liste-Der-Bahnhofe-Im-Raum-Berlin-by-Books-LLC.pdf
    • http://xiixmcuin.linkpc.net/2202204204206205/Assuming-the-Burden-Europe-and-the-American-Commitment-to-War-in-Vietnam-by-Mark-Atwood-Lawrence.pdf
    • http://xiixmcuin.linkpc.net/4208208202208205/Star-Wars-Omnibus---Rise-of-the-Sith-by-Mike-Kennedy.pdf
    • http://xiixmcuin.linkpc.net/5207206208207203/Feminism-Sexuality-and-Politics-Essays-by-Estelle-B-Freedman-by-Estelle-B-Freedman.pdf
    • http://xiixmcuin.linkpc.net/3205204209200205/Robert-F-Kennedy-Ripples-of-Hope-Kerry-Kennedy-in-Conversation-with-Heads-of-State-Business-Leaders-Influencers-and-Activists-about-Her-Father-s-Impact-on-Their-Lives-by-Kerry-Kennedy.pdf
    • http://xiixmcuin.linkpc.net/1200206206208200204/Berlin-Berlin-from-A-Z-Berlin-Biennale-by-Aris-Fioretos.pdf
    • http://xiixmcuin.linkpc.net/9208205203200200/Lady-Chatterley-s-Lover-by-D-H-Lawrence-Illustrated-Delphi-Parts-Edition-D-H-Lawrence-by-D-H-Lawrence.pdf
    • http://xiixmcuin.linkpc.net/1200209202200200200/Barockbauwerk-in-Berlin-Judisches-Museum-Berlin-Schloss-Charlottenburg-Schloss-Schonhausen-Zeughaus-Berlin-Schloss-Kopenick-by-Quelle-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/1206201201208206/The-Missing-Kennedy-Rosemary-Kennedy-and-the-Secret-Bonds-of-Four-Women-by-Elizabeth-Koehler-Pentacoff.pdf
    • http://xiixmcuin.linkpc.net/1200205203204202205/