Malicious PDF — malware analysis report

Static analysis result for SHA-256 da582171c0a84cac…

MALICIOUS

PDF

29.9 KB Created: 2019-04-30 02:14:14 +01:00 Authoring application: mPDF 5.7
MD5: a8b12dcbf1ea3c1ab530dfd753e36dc5 SHA-1: e23125b21472edd8fc3f172a7ecafa5c5b4d5b5a SHA-256: da582171c0a84cacd28d1204f3b6371fb88736d1eae54808dfa0a51ab2310e19
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier as malicious and contains a large number of external links, many of which are numerically generated and point to other PDFs. This suggests a link farm designed to obscure the true malicious intent or to distribute a large volume of content, potentially for SEO poisoning or to host malicious payloads. The primary URL identified is part of this link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201205206209202205/1941-Ships-German-Submarine-U-571-German-Submarine-U-155-German-Submarine-U-459-German-Submarine-U-460-German-Submarine-U-505-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/8206202206209208/German-Children-s-Literature-Max-and-Moritz-the-Neverending-Story-Momo-German-Editions-of-the-Three-Investigators-Struwwelpeter-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/1201200201204206200/Progressive-German-Reader-I---First-Year-Containing-an-Introduction-to-the-German-Order-of-Words-with-Copious-Examples-Extracts-from-German-Authors-in-Prose-and-Poetry-Notes-and-Vocabularies-by-G-Eug-ne-Fasnacht.pdf
    • http://xiixmcuin.linkpc.net/3205209201202/Submarine-by-Joe-Dunthorne.pdf
    • http://xiixmcuin.linkpc.net/1200207207202209/Submarine-Warriors-The-Enemy-Beneath-by-Rob-Tiffany.pdf
    • http://xiixmcuin.linkpc.net/4209208203207209/The-Beatles-Yellow-Submarine-by-Bill-Morrison.pdf
    • http://xiixmcuin.linkpc.net/1201202209206200208/Learn-German-in-a-Hurry-Grasp-the-Basics-of-German-Schnell-by-Edward-Swick.pdf
    • http://xiixmcuin.linkpc.net/1200205203202201209/Bilingual-Book-in-English-and-German-Chameleon---Cham-leon---Learn-German-Collection-by-LingoLibros.pdf
    • http://xiixmcuin.linkpc.net/1201208208202200202/The-20-best-German-Christmas-Cookies---Festive-Baking-Recipes-from-Germany-Pl-tzchen-and-other-German-Holiday-Treats-by-Liane-Guterhof.pdf
    • http://xiixmcuin.linkpc.net/7205200206201208/German-Atrocities-from-German-Evidence-by-Joseph-B-dier.pdf
    • http://xiixmcuin.linkpc.net/8208208203207201/English---German-Dictionary-W-rterbuch-Englisch---Deutsch-Over-25-000-Translations-Learn-How-to-Speak-German-Language-Tools-by-Klaus-R-diger.pdf
    • http://xiixmcuin.linkpc.net/7204202207201200/Sea-Phoenix-A-True-Submarine-Story-by-Mian-Zahir-Shah.pdf
    • http://xiixmcuin.linkpc.net/3208204202206207/Wahoo-The-Patrols-of-America-s-Most-Famous-World-War-II-Submarine-by-Richard-H-O-39-Kane.pdf
    • http://xiixmcuin.linkpc.net/8206202205202/Escape-from-the-Deep-The-Epic-Story-of-a-Legendary-Submarine-and-her-Courageous-Crew-by-Alex-Kershaw.pdf
    • http://xiixmcuin.linkpc.net/1200208204205207207/Red-Star-Rogue-The-Untold-Story-of-a-Soviet-Submarine-s-Nuclear-Strike-Attempt-on-the-U-S-by-Kenneth-Sewell.pdf
    • http://xiixmcuin.linkpc.net/9209202204203206/Analytical-Chemistry-English-German-German-English-by-Technischen-Universitat-Dresden.pdf
    • http://xiixmcuin.linkpc.net/9204205209203203/The-German-Protestant-Church-in-Colonial-Southern-Africa-The-Impact-of-Overseas-Work-from-the-Beginnings-Until-the-1920s-on-Behalf-of-the-Sponsors-and-the-Academic-Advisory-Council-of-the-Study-Process-on-the-Role-of-the-German-Protestant-Work-Oversea-by-Julia-Besten.pdf
    • http://xiixmcuin.linkpc.net/8209205207205200/Guderian-Panzer-s-on-War-1939-1941-by-German-Military-Books-2000--2015.pdf
    • http://xiixmcuin.linkpc.net/9205209207201208/Weiter-Grammatik-German-Reader-Weiter-Grammatik-German-Reader-by-Isabelle-Salaun.pdf
    • http://xiixmcuin.linkpc.net/9204201201208203/Panzer-Colors-II-Markings-of-the-German-Army-Panzer-Forces-1939-45---Specials-series-6017-Markings-of-the-German-Army-Panzer-Forces-1939-45-v-2-by-Bruce-Culver.pdf