Malicious PDF — malware analysis report

Static analysis result for SHA-256 e272abd38990ec54…

MALICIOUS

PDF

16.0 KB Created: 2019-05-02 00:46:54 +01:00 Authoring application: mPDF 5.7
MD5: 1bee7dcf4af114ed5067e25579171386 SHA-1: 40adc32530b5cf3031b9e42c4dc8c355dfe0eeed SHA-256: e272abd38990ec546630bacfeef90b7c9065e7005ac3e73f87b046fe19e42f6e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files, characteristic of a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a collection of potentially malicious or unwanted content hosted on a suspicious domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3207204204202208/Codename-Knockout-Volume-1-The-Devil-You-Say-by-Robert-Rodi.pdf
    • http://xiixmcuin.linkpc.net/1201200209201202206/Loki-by-Robert-Rodi.pdf
    • http://xiixmcuin.linkpc.net/2203204208207201/Bitch-Goddess-by-Robert-Rodi.pdf
    • http://xiixmcuin.linkpc.net/4203209201201208/Thor-Loki-Blood-Brothers-by-Robert-Rodi.pdf
    • http://xiixmcuin.linkpc.net/4204204205203202/Me-and-the-Devil-Blues-The-Unreal-Life-of-Robert-Johnson-Volume-1-by-Akira-Hiramoto.pdf
    • http://xiixmcuin.linkpc.net/9206203209205208/Codename-Litefoot-by-Robert-A-Boyd.pdf
    • http://xiixmcuin.linkpc.net/9206203207209200/Codename-Action-Volume-1-by-Chris-Roberson.pdf
    • http://xiixmcuin.linkpc.net/9206203207202208/Codename-Summer-Codename-Rebellion-4-by-Cyndi-Friberg.pdf
    • http://xiixmcuin.linkpc.net/9206203207208205/Codename-Spring-Codename-Rebellion-3-by-Cyndi-Friberg.pdf
    • http://xiixmcuin.linkpc.net/3200204200201209/Codename-Sailor-V-Vol-2-Codename-Sailor-V-Renewal-Edition-2-by-Naoko-Takeuchi.pdf
    • http://xiixmcuin.linkpc.net/3208207201205208/Legends-1-Volume-1-Volume-2of2-by-Robert-Silverberg.pdf
    • http://xiixmcuin.linkpc.net/2207206205206205/The-Devil-Does-Exist-Volume-1-by-Mitsuba-Takanashi.pdf
    • http://xiixmcuin.linkpc.net/6208204209201203/Confrontations-With-The-Devil-by-Robert-W-Pelton.pdf
    • http://xiixmcuin.linkpc.net/1204206206204201/Knockout-Wayward-Fighters-1-by-J-C-Valentine.pdf
    • http://xiixmcuin.linkpc.net/1207205202207206/The-Knockout-Artist-by-Harry-Crews.pdf
    • http://xiixmcuin.linkpc.net/2200209201207206/The-Japanese-Devil-Fish-Girl-and-Other-Unnatural-Attractions-Japanese-Devil-Fish-Girl-1-by-Robert-Rankin.pdf
    • http://xiixmcuin.linkpc.net/4207201200203202/Wolverines-Volume-1-Dancing-with-the-Devil-by-Charles-Soule.pdf
    • http://xiixmcuin.linkpc.net/2203208202203207/Damned-An-Illustrated-History-of-the-Devil-by-Robert-Muchembled.pdf
    • http://xiixmcuin.linkpc.net/2204209205206201/Stone-Cold-Knockout-House-of-Pain-1-by-Lavender-Parker.pdf
    • http://xiixmcuin.linkpc.net/1201208202204202207/An-Elizabethan-Lawyer-s-Possession-by-the-Devil-The-Story-of-Robert-Brigges-by-Kathleen-R-Sands.pdf
    • http://xiixmcuin.linkpc.net/3208207201205208/Legends-1-Volume-1