Malicious PDF — malware analysis report

Static analysis result for SHA-256 d21e57bccdd4bd43…

MALICIOUS

PDF

23.2 KB Created: 2019-04-30 06:45:42 +01:00 Authoring application: mPDF 5.7
MD5: 0f1a183d23aaeef5689c398fd2e80c48 SHA-1: be865375b68265852ce25606d8e59f45817faed4 SHA-256: d21e57bccdd4bd43471048b07de0778e7cd902cfa135770aaff79119ea7e2df7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely for SEO spam or to distribute further malware. The document body is heavily obfuscated, preventing a clear understanding of its direct purpose beyond hosting these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/6206207204202203/Samantha-s-Wedding-Memories-A-Scrapbook-of-Gard-and-Cornelia-s-Wedding-by-Dan-Andreasen.pdf
    • http://xiixmcuin.linkpc.net/2202209203203206/The-Wedding-Dress-Diaries-The-Wedding-Season-0-5-by-Aimee-Carson.pdf
    • http://xiixmcuin.linkpc.net/3202205207208209/Samantha-Saves-the-Wedding-by-Valerie-Tripp.pdf
    • http://xiixmcuin.linkpc.net/1200200205209209207/Irish-Wedding-Traditions-Using-Your-Irish-Heritage-to-Create-the-Perfect-Wedding-by-Shannon-McMahon-Lichte.pdf
    • http://xiixmcuin.linkpc.net/3204208209206208/The-Wedding-Rescue-Complete-Series-The-Wedding-Rescue-1-5-by-Alexa-Wilder.pdf
    • http://xiixmcuin.linkpc.net/6206207204209203/Plaats-in-Gard-Gemeente-in-Gard-Nimes-Pont-Du-Gard-Nemausus-Lijst-Van-Gemeenten-in-Het-Departement-Gard-Nimes-Olympique-Maison-Carree-by-Bron-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/3205208200202205/The-Wedding-Tree-The-Wedding-Tree-1-by-Robin-Wells.pdf
    • http://xiixmcuin.linkpc.net/1201201208202205207/The-Wedding-Planner-s-Daughter-Wedding-Planner-s-Daughter-1-by-Coleen-Murtagh-Paratore.pdf
    • http://xiixmcuin.linkpc.net/2209202206208205/The-Wedding-Man-by-H-M-Trey.pdf
    • http://xiixmcuin.linkpc.net/6209205206203205/Papillon-May-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206203209/Papillon-April-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206203206/Papillon-February-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206204206/Papillon-December-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206204205/Papillon-March-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/6209205206204200/Papillon-January-Notebook-Papillon-Record-Log-Diary-Special-Memories-to-Do-List-Academic-Notepad-Scrapbook-amp-More-by-Papillon.pdf
    • http://xiixmcuin.linkpc.net/5207200203205204/Wedding-Peach-Vol-03-by-Nao-Yazawa.pdf
    • http://xiixmcuin.linkpc.net/2207207209204209/Werewolf-Wedding-by-L-Vanhorn.pdf
    • http://xiixmcuin.linkpc.net/3207202209203/That-Wedding-That-Boy-2-by-Jillian-Dodd.pdf
    • http://xiixmcuin.linkpc.net/3202205200204203/Whose-Wedding-Is-It-Anyway-by-Melissa-Senate.pdf
    • http://xiixmcuin.linkpc.net/9209209205207205/The-Wedding-by-Elias-Canetti.pdf
    • http://xiixmcuin.linkpc.net/6206207204209203/Plaats-in-Gard-Gemeente-in-Gard-Nimes-Pont-Du-Gard-Nemausus-Lijst-Van-Gemeenten-in-Het-Departement-Gard-Nimes-Olympique-Maison-Carree-by-Bron-Wikiped