Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecd066a8018ec12d…

MALICIOUS

PDF

17.4 KB Created: 2019-04-24 23:41:47 +01:00 Authoring application: mPDF 5.7
MD5: 0a54a80d103519c8cba050301b622c16 SHA-1: 8a691943904d62a25d751254bdc393adf216a217 SHA-256: ecd066a8018ec12d318cb8ac2b529e201d1dacb4bb777abf79f40a48caee789e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of embedded links to external PDFs, indicating a link farm or redirection scheme. The heuristic PDF_SEO_LINK_FARM specifically identified 23 external links, with the first being http://tuckeiao.dyndns.co.za/4022020026021026/Katherine-Mansfield-Letters-And-Journals-A-Selection-by-Katherine-Mansfield.pdf. This suggests the document's primary purpose is to direct users to potentially malicious content hosted on the tuckeiao.dyndns.co.za domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tuckeiao.dyndns.co.za/4022020026021026/Katherine-Mansfield-Letters-And-Journals-A-Selection-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/3022027024022024/The-Complete-Stories-Of-Katherine-Mansfield-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/4024023020025025/Stories-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/4020021028029024/Something-Childish-and-Other-Stories-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/6022029025022024/The-Doll-s-House-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/3028026020025026/Bliss-and-Other-Stories-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/6023023023022027/The-Garden-Party-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/7022024024023021/Pension-allemande-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/4020027026023026/The-Garden-Party-and-Other-Stories-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/3028026022027029/In-a-German-Pension-13-Stories-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/1021028028027027022/Garden-Party-and-Other-Stories-by-Katherine-Mansfield.pdf
    • http://tuckeiao.dyndns.co.za/6023023024020024/Katherine-Mansfield-A-Darker-View-by-Jeffrey-Meyers.pdf
    • http://tuckeiao.dyndns.co.za/6023023023022024/The-Return-of-Connor-Mansfield-The-Mansfield-Brothers-1-by-Beth-Cornelison.pdf
    • http://tuckeiao.dyndns.co.za/1020028021027027/The-Mansfield-Rescue-The-Mansfield-Brothers-3-by-Beth-Cornelison.pdf
    • http://tuckeiao.dyndns.co.za/5022024027028023/Jane-Austen---Le-Parc-de-Mansfield-ou-les-Trois-cousines---4-Tomes---annot-Titre-original-Mansfield-Park-by-Jane-Austen.pdf
    • http://tuckeiao.dyndns.co.za/8024025027028/Batman-Prelude-to-the-Wedding-Batgirl-vs-Riddler-2018--1-Batman-Prelude-to-the-Wedding-2018--by-Tim-Seeley.pdf
    • http://tuckeiao.dyndns.co.za/8023024027023/Batman-Prelude-to-the-Wedding-Nightwing-vs-Hush-2018--1-Batman-Prelude-to-the-Wedding-2018--by-Tim-Seeley.pdf
    • http://tuckeiao.dyndns.co.za/8021028026021023/Prelude-Creatura-0-5-by-Nely-Cab.pdf
    • http://tuckeiao.dyndns.co.za/3028029027023/Prelude-to-Foundation-by-Isaac-Asimov.pdf
    • http://tuckeiao.dyndns.co.za/3024022028023026/Prelude-To-A-Song-by-Margaret-Pargeter.pdf