Malicious PDF — malware analysis report

Static analysis result for SHA-256 d976aba74348f6dc…

MALICIOUS

PDF

19.3 KB Created: 2019-05-03 05:39:15 +01:00 Authoring application: mPDF 5.7
MD5: 06d2464a438dfa697cb025a7f1daf6fb SHA-1: e8812dafe1313e068c7f29554f0b5ef64734433f SHA-256: d976aba74348f6dccab8f228f98f13a64b05125694c036bdae0b832527c184ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents, characteristic of a link farm. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic identified the link farm pattern. While no scripts were extracted, the primary attack vector appears to be directing users to a potentially malicious collection of external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200208207202202205/The-Sociology-of-Revolution-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207203205200/Sociological-Theory-Values-and-Sociocultural-Change-Essays-in-Honor-of-Pitirim-A-Sorokin-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207203204202/The-Reconstruction-of-Humanity-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207201204204/Man-and-Society-in-Calamity-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207202202207/Power-and-Morality-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207201204206/Social-And-Cultural-Mobility-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207202202200/Hunger-As-a-Factor-in-Human-Affairs-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207203204200/Explorations-in-Altruistic-Love-and-Behavior-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207203204209/History-Civilization-And-Culture-An-Introduction-To-The-Historical-And-Social-Philosophy-Of-Pitirim-A-Sorokin-by-Frank-A-Cowell.pdf
    • http://xiixmcuin.linkpc.net/1200208207201203203/Social-and-Cultural-Dynamics-A-Study-of-Change-in-Major-Systems-of-Art-Truth-Ethics-Law-and-Social-Relationships-by-Pitirim-A-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/6206205201202205/India-s-Changing-Villages-International-Library-of-Sociology-E-The-Sociology-of-Development-by-S-C-Dube.pdf
    • http://xiixmcuin.linkpc.net/1200208207203209200/LURGO-by-Serg-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/8206201209209200/Under-the-Canopy-by-Serg-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207203209208/Coral-Reef-Ecology-by-Iu-I-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207203209203/Russkie-Povesti-by-Aleksandr-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/1200208207203203207/Nonprofit-Governance-and-Management-by-Cherie-Sorokin.pdf
    • http://xiixmcuin.linkpc.net/8205206208208201/The-Old-Regime-and-the-Revolution-Volume-II-Notes-on-the-French-Revolution-and-Napoleon-by-Alexis-de-Tocqueville.pdf
    • http://xiixmcuin.linkpc.net/1206208202205209/The-Mexican-Revolution-Volume-2-Counter-revolution-and-Reconstruction-by-Alan-Knight.pdf
    • http://xiixmcuin.linkpc.net/2209208201206200/From-Revolution-to-Revolution-Perspectives-on-Publishing-amp-Bookselling-by-Leona-Rostenberg.pdf
    • http://xiixmcuin.linkpc.net/6207205201203207/Sociology-for-A2-AQA-by-Jonathan-Blundell.pdf