Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1ef62447a6c2a99…

MALICIOUS

PDF

18.5 KB Created: 2019-04-30 05:51:09 +01:00 Authoring application: mPDF 5.7
MD5: ad42375cd919ecf1d367dac99469ab93 SHA-1: 6e137e42aa002b4cafbeddfaf87761ccd65747f3 SHA-256: d1ef62447a6c2a993bbe82b9788adf594ec7fa7235d08d187e25a37966343e37
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, hosted on a dynamic DNS domain. This behavior is indicative of a link farm or SEO poisoning attack, designed to drive traffic to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2206205203207208/On-Tyranny-Twenty-Lessons-from-the-Twentieth-Century-by-Timothy-Snyder.pdf
    • http://xiixmcuin.linkpc.net/5201202206/On-Tyranny-Twenty-Lessons-from-the-Twentieth-Century-by-Timothy-Snyder.pdf
    • http://xiixmcuin.linkpc.net/1201204209203209208/Eight-Twentieth-Century-Russian-Plays-by-Timothy-Langen.pdf
    • http://xiixmcuin.linkpc.net/8205206209208204/The-Devil-in-History-Communism-Fascism-and-Some-Lessons-of-the-Twentieth-Century-by-Vladimir-Tism-neanu.pdf
    • http://xiixmcuin.linkpc.net/3208205206208209/The-Oxford-History-of-the-British-Empire-Volume-IV-The-Twentieth-Century-Twentieth-Century-Vol-4-by-Judith-M-Brown.pdf
    • http://xiixmcuin.linkpc.net/1201200202201200/Our-More-Perfect-Union-From-Eighteenth-Century-Principles-to-Twentieth-Century-Practice-by-Arthur-Norman-Holcombe.pdf
    • http://xiixmcuin.linkpc.net/8205207203203203/Tyranny-Unmasked-an-Answer-to-a-Late-Pamphlet-By-S-Johnson-Entitled-Taxation-No-Tyranny-by-Tyranny.pdf
    • http://xiixmcuin.linkpc.net/4204203206205208/Bloodlands-Europe-Between-Hitler-and-Stalin-by-Timothy-Snyder.pdf
    • http://xiixmcuin.linkpc.net/7208209208/The-Road-to-Unfreedom-Russia-Europe-America-by-Timothy-Snyder.pdf
    • http://xiixmcuin.linkpc.net/7202209202209207/Terres-de-sang---L-Europe-entre-Hitler-et-Staline-by-Timothy-Snyder.pdf
    • http://xiixmcuin.linkpc.net/2207203206204208/Nullification-How-to-Resist-Federal-Tyranny-in-the-21st-Century-by-Thomas-E-Woods-Jr-.pdf
    • http://xiixmcuin.linkpc.net/8206200202208204/Art-of-the-Twentieth-Century-by-Ingo-F-Walther.pdf
    • http://xiixmcuin.linkpc.net/4205207201205/From-the-End-of-the-Twentieth-Century-by-John-M-Ford.pdf
    • http://xiixmcuin.linkpc.net/1205204206208208/Paris-in-the-Twentieth-Century-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/4204207204201201/The-Man-Who-Invented-the-Twentieth-Century-by-Robert-Lomas.pdf
    • http://xiixmcuin.linkpc.net/9202203205205/In-Europe-Travels-Through-the-Twentieth-Century-by-Geert-Mak.pdf
    • http://xiixmcuin.linkpc.net/3202209202201202/Allergic-to-the-Twentieth-Century-by-Peter-Radetsky.pdf
    • http://xiixmcuin.linkpc.net/1200202200205202206/Saga-Into-the-Twentieth-Century-by-Louise-Haeger.pdf
    • http://xiixmcuin.linkpc.net/1205207208203/Other-Criteria-Confrontations-with-Twentieth-Century-Art-by-Leo-Steinberg.pdf
    • http://xiixmcuin.linkpc.net/3203207206206209/Twentieth-Century-Scottish-Poems-by-Douglas-Dunn.pdf
    • http://xiixmcuin.linkpc.net/1201200202201200/Our-More-Perfect-Union-From-Eighteenth-Centur