Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec6a03b7d3c8372f…

MALICIOUS

PDF

20.4 KB Created: 2019-04-30 09:03:04 +01:00 Authoring application: mPDF 5.7
MD5: 20a74bf5d53b1818c00ab698c9c80b7f SHA-1: 225d67057e7c77b96c6eefe79a2512cd95adda80 SHA-256: ec6a03b7d3c8372f9b27131e63c3b39a9b6349e6cc2958ebcc34782bfc9bb7aa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which point to external PDF documents. While the ML classifier strongly indicates maliciousness, the specific intent appears to be a link farm designed to drive traffic to a collection of other documents, rather than executing a direct payload from this file. The majority of the extracted URLs were confirmed as benign, suggesting the primary malicious function is the distribution of links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc
    • http://zacdsa.linkpc.net/1c51c51c59c57c59/Mr-Darcy-Takes-a-Wife-Pride-and-Prejudice-Continues-Darcy-amp-Elizabeth-1-by-Linda-Berdoll.pdf
    • http://zacdsa.linkpc.net/2c58c51c58c57c56/Georgiana-Darcy-s-Diary-Jane-Austen-s-Pride-and-Prejudice-Continued-Pride-and-Prejudice-Chronicles-1-by-Anna-Elliott.pdf
    • http://zacdsa.linkpc.net/3c58c59c56c59c51/The-Darcy-Brothers-A-Pride-and-Prejudice-Variation-by-Abigail-Reynolds.pdf
    • http://zacdsa.linkpc.net/1c55c50c58c55c54/Darcy-s-Highland-Fling-A-Pride-and-Prejudice-Variation-by-M-A-Sandiford.pdf
    • http://zacdsa.linkpc.net/2c58c51c58c57c51/Mr-Darcy-s-Letter-A-Pride-amp-Prejudice-Variation-by-Abigail-Reynolds.pdf
    • http://zacdsa.linkpc.net/2c58c51c58c57c57/Darcy-on-the-Hudson-A-Pride-and-Prejudice-Re-imagining-by-Mary-Lydon-Simonsen.pdf
    • http://zacdsa.linkpc.net/4c52c59c51c54/Mr-Fitzwilliam-Darcy-The-Last-Man-in-the-World-A-Pride-and-Prejudice-Variation-by-Abigail-Reynolds.pdf
    • http://zacdsa.linkpc.net/2c58c52c51c56c59/President-Darcy-A-Modern-Pride-and-Prejudice-Variation-by-Victoria-Kincaid.pdf
    • http://zacdsa.linkpc.net/2c58c52c50c52c58/Mr-Darcy-Likes-It-Wild-A-Pride-and-Prejudice-Diversion-by-Beth-Massey.pdf
    • http://zacdsa.linkpc.net/9c51c58c54c59c53/Mr-Darcy-to-the-Rescue-A-Pride-and-Prejudice-Regency-Variation-by-Diana-Enright.pdf
    • http://zacdsa.linkpc.net/2c58c52c54c52c55/Mr-Darcy-s-Pole-A-Pride-and-Prejudice-Sexy-Modern-Variation-by-Nikki-Bliss.pdf
    • http://zacdsa.linkpc.net/1c51c50c55c56c58c58/Georgiana-Darcy-A-Sequel-to-Jane-Austen-s-Pride-and-Prejudice-by-Alice-Isakova.pdf
    • http://zacdsa.linkpc.net/3c59c50c50c57c55/The-Mysterious-Death-of-Mr-Darcy-Pride-and-Prejudice-Murder-Mystery-3-by-Regina-Jeffers.pdf
    • http://zacdsa.linkpc.net/5c55c55c50c59c52/Miss-Darcy-s-Beaux-A-Persuasion-Mansfield-Park-and-Pride-and-Prejudice-Continuation-Austeniana-1-by-Eliza-Shearer.pdf
    • http://zacdsa.linkpc.net/1c52c56c54c53c52/The-Exploits-amp-Adventures-of-Miss-Alethea-Darcy-Darcy-2-by-Elizabeth-Aston.pdf
    • http://zacdsa.linkpc.net/3c58c59c53c55c51/Darcy-s-Passions-Fitzwilliam-Darcy-s-Story-by-Regina-Jeffers.pdf
    • http://zacdsa.linkpc.net/9c51c53c53c59/In-the-Arms-of-Mr-Darcy-Darcy-Saga-4-by-Sharon-Lathan.pdf
    • http://zacdsa.linkpc.net/4c58c54c55c59c50/The-Dating-Mr-Darcy-Trilogy-Prada-and-Prejudice-Love-and-Liability-Mansfield-Lark-by-Katie-Oliver.pdf
    • http://zacdsa.linkpc.net/2c58c51c59c59c55/The-Darcy-Connection-by-Elizabeth-Aston.pdf
    • http://zacdsa.linkpc.net/2c58c52c50c52c57/Becoming-Elizabeth-Darcy-by-Mary-Lydon-Simonsen.pdf