Malicious PDF — malware analysis report

Static analysis result for SHA-256 d32a2714874dad59…

MALICIOUS

PDF

20.0 KB Created: 2019-05-03 05:33:46 +01:00 Authoring application: mPDF 5.7
MD5: 12358577bbd3837fbe173b3692c1e786 SHA-1: 584a004d3091013c4b890aa27ed8eecafb1048dd SHA-256: d32a2714874dad5948b98981f5f0d483750d41162dcc8b365874e2b2ebdf6b7f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the dynamic DNS domain 'cmeinasaoo.duckdns.org'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cmeinasaoo.duckdns.org/9b21b28b29b26b23/A-User-s-Guide-to-the-Universe-Surviving-the-Perils-of-Black-Holes-Time-Paradoxes-and-Quantum-Uncertainty-by-Dave-Goldberg.pdf
    • http://cmeinasaoo.duckdns.org/2b29b25b21b29b28/Homes-and-Other-Black-Holes-by-Dave-Barry.pdf
    • http://cmeinasaoo.duckdns.org/2b25b29b25b28b23/A-Brief-History-Of-Time-From-the-Big-Bang-To-Black-Holes-by-Stephen-Hawking.pdf
    • http://cmeinasaoo.duckdns.org/1b23b27b24b23b23/The-Grand-Design-A-Simply-Stated-User-Friendly-Guide-to-Living-in-the-Universe-by-Paddy-McMahon.pdf
    • http://cmeinasaoo.duckdns.org/9b29b26b20b29b24/Spooky-Action-at-a-Distance-The-Phenomenon-That-Reimagines-Space-and-Time-and-What-It-Means-for-Black-Holes-the-Big-Bang-and-Theories-of-Everything-by-George-Musser.pdf
    • http://cmeinasaoo.duckdns.org/6b24b24b25b25b23/Black-Holes-by-Jean-Pierre-Luminet.pdf
    • http://cmeinasaoo.duckdns.org/2b25b29b26b20b27/Black-Holes-and-Uncle-Albert-by-Russell-Stannard.pdf
    • http://cmeinasaoo.duckdns.org/7b27b24b20b24b25/Black-Holes-The-Reith-Lectures-by-Stephen-Hawking.pdf
    • http://cmeinasaoo.duckdns.org/4b24b28b23b23b26/The-Undivided-Universe-An-Ontological-Interpretation-of-Quantum-Theory-by-David-Bohm.pdf
    • http://cmeinasaoo.duckdns.org/5b27b22b23b29b25/Out-of-Time-The-Pleasures-and-the-Perils-of-Ageing-by-Lynne-Segal.pdf
    • http://cmeinasaoo.duckdns.org/4b24b27b22b27b23/Programming-The-Universe-A-Quantum-Computer-Scientist-Takes-on-the-Cosmos-by-Seth-Lloyd.pdf
    • http://cmeinasaoo.duckdns.org/9b20b21b24b27/A-Simpler-Guide-to-Gmail-An-Unofficial-User-Guide-to-Setting-Up-and-Using-Gmail-Inbox-and-Google-Calendar-by-Ceri-Clark.pdf
    • http://cmeinasaoo.duckdns.org/1b21b25b28b22b29b20/Kindle-User-s-Guide-by-Amazon.pdf
    • http://cmeinasaoo.duckdns.org/1b20b20b24b21/Economics-The-User-s-Guide-by-Ha-Joon-Chang.pdf
    • http://cmeinasaoo.duckdns.org/6b23b26b25b28b28/Kindle-Paperwhite-User-s-Guide-by-Amazon.pdf
    • http://cmeinasaoo.duckdns.org/4b25b27/Kindle-Paperwhite-User-s-Guide-by-Amazon.pdf
    • http://cmeinasaoo.duckdns.org/1b20b24b21b27b22b29/Stanley-Yelnats-Survival-Guide-to-Camp-Green-Lake-Holes-1-5-by-Louis-Sachar.pdf
    • http://cmeinasaoo.duckdns.org/2b22b26b21b26b22/The-Bill-of-Rights-A-User-s-Guide-by-Linda-R-Monk.pdf
    • http://cmeinasaoo.duckdns.org/3b23b20b24b29b22/Advanced-Day-Planner-User-s-Guide-by-Hyrum-W-Smith.pdf
    • http://cmeinasaoo.duckdns.org/1b20b21b25b22b25b23/Voodoo-Rituals-A-User-s-Guide-by-Heike-Owusu.pdf
    • http://cmeinasaoo.duckdns.org/9b29b26b20b29b24/Spooky-Action-at-a-Distance-The-Phenomenon-That-Reimagines-Space-and-Time-and-What-It-Means-for-Black-Holes-the-Big-Bang-and-Theorie