Malicious PDF — malware analysis report

Static analysis result for SHA-256 e39b6f6c831247fe…

MALICIOUS

PDF

19.8 KB Created: 2019-05-26 12:04:07 +01:00 Authoring application: mPDF 5.7
MD5: d70c768b613fa0ef2b501909dede03e9 SHA-1: 582658564965a90fbdc137360354543bcc9ab756 SHA-256: e39b6f6c831247fec645e6f48e6348640bef2b2e9a49033f538c821e3d010444
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://leakscaioiobook.4dq.com/5d0c4d0c6d0c5d0c5d0c3/More-Mouse-Tales-A-Closer-Peek-Backstage-at-Disneyland-by-David-Koenig.pdf
    • http://leakscaioiobook.4dq.com/5d0c4d0c6d0c5d0c6d0c1/Mouse-Under-Glass-Secrets-of-Disney-Animation-and-Theme-Parks-by-David-Koenig.pdf
    • http://leakscaioiobook.4dq.com/4d0c8d0c5d0c7d0c1d0c5/Mouse-Moments---A-Humorous-Guide-Through-Disneyland-by-Deirdre-A-Sargent.pdf
    • http://leakscaioiobook.4dq.com/1d0c1d0c5d0c2d0c7d0c7d0c4/Disneyland-The-Nickel-Tour-by-David-Kent-Mumford.pdf
    • http://leakscaioiobook.4dq.com/2d0c3d0c8d0c6d0c4/Mouse-Guard-Fall-1152-Mouse-Guard-1-by-David-Petersen.pdf
    • http://leakscaioiobook.4dq.com/6d0c1d0c6d0c9d0c8d0c4/THE-KEY-OF-GOLD-23-Czech-Folk-and-Fairy-Tales-Tales-from-Ancient-Bohemia-Moravia-and-Czech-Silesia-by-Anon-E-Mouse.pdf
    • http://leakscaioiobook.4dq.com/1d0c3d0c5d0c0d0c8d0c5/Backstage-Pass-Behind-the-Music-The-Backstage-Pass-Rock-Star-Romance-4-by-Elizabeth-Nelson.pdf
    • http://leakscaioiobook.4dq.com/4d0c7d0c8d0c7d0c1d0c1/Realityland-True-Life-Adventures-at-Walt-Disney-World-by-David-Koenig.pdf
    • http://leakscaioiobook.4dq.com/2d0c0d0c3d0c2d0c5/Closer-and-Closer-Enclave-1-by-Jenna-Barton.pdf
    • http://leakscaioiobook.4dq.com/4d0c6d0c3d0c0d0c4d0c5/The-Cat-and-the-Mouse-A-Book-of-Persian-Fairy-Tales-by-Hartwell-James.pdf
    • http://leakscaioiobook.4dq.com/8d0c1d0c0d0c6d0c4d0c0/Water-Torture-the-Barking-Mouse-and-other-tales-of-wonder-by-Antonio-Sacre.pdf
    • http://leakscaioiobook.4dq.com/7d0c8d0c1d0c9d0c7d0c5/Sumo-Mouse-by-David-Wisniewski.pdf
    • http://leakscaioiobook.4dq.com/8d0c7d0c3d0c9d0c9d0c4/Mouse-Guard-The-Dark-Ghost-Fall-1152-4-by-David-Petersen.pdf
    • http://leakscaioiobook.4dq.com/4d0c9d0c6d0c2d0c8d0c1/The-Mouse-on-Wall-Street-The-Mouse-That-Roared-3-by-Leonard-Wibberley.pdf
    • http://leakscaioiobook.4dq.com/4d0c6d0c5d0c3d0c9d0c4/The-Mouse-on-the-Moon-The-Mouse-That-Roared-2-by-Leonard-Wibberley.pdf
    • http://leakscaioiobook.4dq.com/4d0c7d0c1d0c3d0c9d0c5/The-Mouse-and-the-Motorcycle-Ralph-S-Mouse-1-by-Beverly-Cleary.pdf
    • http://leakscaioiobook.4dq.com/4d0c4d0c2d0c7d0c0d0c1/Mouse-Guard-Labyrinth-and-Other-Stories-Free-Comic-Book-Day-2012-by-David-Petersen.pdf
    • http://leakscaioiobook.4dq.com/3d0c6d0c5d0c0d0c6d0c1/Town-Mouse-Country-Mouse-by-Jan-Brett.pdf
    • http://leakscaioiobook.4dq.com/2d0c9d0c2d0c9d0c7d0c7/Tales-of-the-Resistance-Tales-of-the-Kingdom-2-by-David-R-Mains.pdf
    • http://leakscaioiobook.4dq.com/2d0c3d0c8d0c1d0c5/Mouse-Guard-Legends-of-the-Guard-Vol-1-by-David-Petersen.pdf
    • http://leakscaioiobook.4dq.com/6d0c1d0c6d0c9d0c8d0c4/THE-KEY-OF-GOLD-23-Czech-Folk-and-Fairy-Tales-Tales-from-Ancient-Bohemia-Moravia-and-Czech-Silesia-by-Anon-E-Mouse.pd