Malicious PDF — malware analysis report

Static analysis result for SHA-256 b56db09598d98dbe…

MALICIOUS

PDF

24.3 KB Created: 2019-05-07 09:25:03 +01:00 Authoring application: mPDF 5.7
MD5: fa3417a3e8d91e38065243a164e386cf SHA-1: b8d44ff026f9c596604fd87854dc591f0db362f0 SHA-256: b56db09598d98dbeb434122fcba83a28be35f8cde7c43b1072d3f1badb09e918
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific content of these linked PDFs is benign, the sheer volume and structure suggest an attempt to manipulate search engine results or distribute content through a link farm. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc.net/6c56c58c52c58c55/Lewis-Carroll-Box-Set-Alice-Adventures-in-Wonderland-and-Through-the-Looking-Glass-Including-the-Short-Film-the-Delivery-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/5c54c51c50c52c52/Alice-s-Adventures-in-Wonderland-By-Lewis-Carroll---Illustrated-Comes-with-a-Free-Audiobook-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/9c57c50c53c58c59/Alice-Lewis-Carroll-Lewis-Carroll-Alice-Im-Wunderland-Vladimir-Nabokov-Das-Spiegellabyrinth-Alice-in-Wonderland-Humpty-Dumpty-Alice-Liddell-John-Tenniel-Cheshire-Cat-Der-Hutmacher-Christian-Enzensberger-by-Source-Wikipedia.pdf
    • http://zacdsa.linkpc.net/3c54c59c51c52c53/Alice-s-Adventures-in-Wonderland-By-Lewis-Carroll-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/6c55c52c53c54c54/Alice-s-Adventures-in-Wonderland-And-Through-the-Looking-Glass-amp-What-Alice-Found-There-By-Lewis-Carroll-Illustrations-By-John-Tenniel-Children-s-Classics-Sir-John-Tenniel-27-July-1819---25-February-1914-Was-an-English-Illustrator-Graphic-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/8c57c56c59c50/The-Collected-Stories-of-Lewis-Carroll-Alice-in-Wonderland-Through-the-Looking-Glass-Phantasmagoria-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/7c50c54c53c59c51/Alice-in-Wonderland-And-Through-The-Looking-Glass-By-Lewis-Carroll---Illustrated-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/3c55c59c50c56c53/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/8c54c50c53c53/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/9c52c57c59c55c58/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/6c56c52c59c50c50/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/8c57c52c51c54c51/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/4c57c50c53c50c57/Alice-s-Adventures-In-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/2c57c52c54c54c52/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/1c50c58c53c57c59c58/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/5c58c53c59c58/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/1c50c55c54c58c58c59/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/7c56c55c52c58c52/Alice-s-adventures-in-Wonderland-and-Through-the-looking-glass-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/8c52c55c53c52c57/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
    • http://zacdsa.linkpc.net/1c51c53c54c58c57c52/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf