Malicious PDF — malware analysis report

Static analysis result for SHA-256 c35ce8b9b735d68e…

MALICIOUS

PDF

23.0 KB Created: 2020-02-05 19:34:18 +00:00 Authoring application: mPDF 5.7
MD5: adeae45bbda94584ce9346bd81121638 SHA-1: 0425d33ec17e74ddbea522687117154a36d62da7 SHA-256: c35ce8b9b735d68eb7f4e2266a56956414ad75ccb1b7f71e958320b4eb06045e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to external documents, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tuiwckiko.jpn.ph/85d45d95d05d95d0/Frankenstein-Mary-Shelley-The-Modern-Prometheus-Frankenstein-s-Monster-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/55d35d05d05d55d3/Frankenstein-or-The-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/85d45d45d95d75d6/Frankenstein-Or-the-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/65d55d35d25d85d5/Frankenstein-or-The-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/55d45d25d45d05d0/Frankenstein-or-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/75d15d65d85d05d9/Frankenstein-Or-The-Modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/85d85d15d75d05d7/Frankenstein-or-The-modern-Prometheus-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/65d75d15d25d75d9/Frankenstein-or-the-Modern-Prometheus---also-includes-an-annotated-bibliography-on-select-works-of-Science-Fiction-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/75d05d55d45d85d1/Frankenstein-Or-the-Modern-Prometheus-original-uncensored-1818-version-Food-in-Literature-and-Culture-Edition-annotated-amp-unabridged-The-Story-at-the-End-of-the-Fork-Series-Book-2-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/75d35d15d95d45d0/Frankenstein-or-The-Modern-Prometheus-Companion-Includes-Study-Guide-Complete-Unabridged-Book-Historical-Context-Biography-Character-Index-and-Unabridged-Book-Annotated-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/75d15d35d15d05d9/Frankenstein-By-Mary-Wollstonecraft-Shelley-amp-Illustrated-An-Audiobook-Free-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/85d25d65d35d55d5/The-Frankenstein-Notebooks-A-Facsimile-Edition-of-Mary-Shelley-s-Manuscript-Novel-1816-17-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/15d95d05d45d55d5/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/75d95d25d15d25d1/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/65d05d25d35d05d0/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/85d55d85d05d65d3/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/35d15d55d65d45d2/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/55d45d35d05d65d0/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/15d05d45d25d15d7/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/45d05d25d65d45d3/Frankenstein-by-Mary-Wollstonecraft-Shelley.pdf
    • http://tuiwckiko.jpn.ph/65d75d15d25d75d9/Frankenstein-or-the-Modern-Prometheus---also-includes-an-annotated-bibliography-on-sel