Malicious PDF — malware analysis report

Static analysis result for SHA-256 d01e474671b01401…

MALICIOUS

PDF

21.6 KB Created: 2019-04-30 09:27:35 +01:00 Authoring application: mPDF 5.7
MD5: 0d4f0d7a3dab215405b61c6284a382d9 SHA-1: 5cbc66649eb9edbb5b69f03447c5592f3d9907e5 SHA-256: d01e474671b01401f85e0acee940c29fad5f8a5dbcf28a4d95f9a7dba9631bda
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm. While the specific URLs appear benign, the sheer volume and the heuristic firing indicate a likely attempt to distribute unwanted content or engage in SEO manipulation for malicious purposes. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201202202208201205/Otome-no-nitijou-Tokiwa-Sayuri-Lite-007-by-HoneyRabbit.pdf
    • http://xiixmcuin.linkpc.net/1201202202208201206/Otome-no-nitijou-Tokiwa-Sayuri-Lite-004-by-HoneyRabbit.pdf
    • http://xiixmcuin.linkpc.net/1201202202208201207/Otome-no-nitijou-Tokiwa-Sayuri-Lite-008-by-HoneyRabbit.pdf
    • http://xiixmcuin.linkpc.net/1201202202205208203/Sayuri-s-Food-for-Yogis-and-Everyone-Easy-delicious-healthy-vegan-recipes-with-gluten-free-alternatives-which-Sayuri-prepares-at-yoga-retreats-around-and-detox-Sayuri-s-Vegan-cookbook-Book-1-by-Sayuri-Tanaka.pdf
    • http://xiixmcuin.linkpc.net/1201202202207201208/Sayuri-s-Raw-Food-Cafe-Easy-Delicious-Healthy-Raw-vegan-vegetarian-gluten-free-diet-and-dessert-to-nourish-your-body-and-heart-as-well-as-healing-and-Sayuri-s-Raw-Food-cookbook-Book-1-by-Sayuri-Tanaka.pdf
    • http://xiixmcuin.linkpc.net/1206204201207206/-Otome-no-mikkoku-by-Akiko-Akazome.pdf
    • http://xiixmcuin.linkpc.net/2200205203205202/Rapper-s-D-Lite-by-Sa-39-id-Salaam.pdf
    • http://xiixmcuin.linkpc.net/5200206204202205/Lite-mer-n-en-kram-by-M-rten-Melin.pdf
    • http://xiixmcuin.linkpc.net/8201206204/A-Lite-Too-Bright-by-Samuel-Miller.pdf
    • http://xiixmcuin.linkpc.net/1207208201207206/Blood-Lite-Hellchaser-0-5-by-Kevin-J-Anderson.pdf
    • http://xiixmcuin.linkpc.net/1201202202206200200/Untamed-by-Sayuri-Nagasaki.pdf
    • http://xiixmcuin.linkpc.net/1201202202204207201/BECAUSE-I-M-A-MAID-Episode-4-by-Sayuri-Sakai.pdf
    • http://xiixmcuin.linkpc.net/1201202202207200209/I-Still-Love-You-Even-Wake-Up-from-My-Dream-by-Sayuri-Miroku.pdf
    • http://xiixmcuin.linkpc.net/1201202202205209201/dutch-wife-sayuri-syasinsyuu-vol1-by-NOSTYLE.pdf
    • http://xiixmcuin.linkpc.net/1201202202205202200/BECAUSE-I-M-A-MAID-Episode-7-The-Darkness-in-the-Heart-by-Sayuri-Sakai.pdf
    • http://xiixmcuin.linkpc.net/6207200204201200/Precede-with-Caution-Bekan-s-Quest-A-Lite-Farie-Tale-3-by-Alexandria-Infante.pdf
    • http://xiixmcuin.linkpc.net/1200205206208206206/--6-Tasogare-Otome-Amnesia-6-Dusk-Maiden-of-Amnesia-6-by-Maybe.pdf
    • http://xiixmcuin.linkpc.net/1201202202206200204/Transpacific-Field-of-Dreams-How-Baseball-Linked-the-United-States-and-Japan-in-Peace-and-War-by-Sayuri-Guthrie-Shimizu.pdf
    • http://xiixmcuin.linkpc.net/6209208204203208/Blood-Lite-An-Anthology-of-Humorous-Horror-Stories-Presented-by-the-Horror-Writers-Association-by-Kevin-J-Anderson.pdf
    • http://xiixmcuin.linkpc.net/1201202202208201209/binibonnhonpo-sayuri-syasinsyuu-vol5-binibonhonpo-syasinsyuu-by-NOSTYLE.pdf
    • http://xiixmcuin.linkpc.net/1206204201207206/-Otome-no-mikkoku-by-Akik