Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7c0084b5d1692c6…

MALICIOUS

PDF

16.8 KB Created: 2019-05-02 17:20:18 +01:00 Authoring application: mPDF 5.7
MD5: c74e5df33c356028f78b4765281bc258 SHA-1: 4aa96a70bc88658654917ee93ac2d9893a0b8dc6 SHA-256: f7c0084b5d1692c6abe69b6ed852bda992b7692c7bf66606c58b8c431ff6da10
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links, such as http://xiixmcuin.linkpc.net/1200203208205205205/Thinker-On-Stage-Nietzsche-s-Materialism-by-Peter-Sloterdijk.pdf, likely lead to a malicious website or download. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200203208205205205/Thinker-On-Stage-Nietzsche-s-Materialism-by-Peter-Sloterdijk.pdf
    • http://xiixmcuin.linkpc.net/1200203208208204209/Sph-ren-Bde-1-3-by-Peter-Sloterdijk.pdf
    • http://xiixmcuin.linkpc.net/8208208203207205/Esferas-I-by-Peter-Sloterdijk.pdf
    • http://xiixmcuin.linkpc.net/1200203208204209200/You-Must-Change-Your-Life-by-Peter-Sloterdijk.pdf
    • http://xiixmcuin.linkpc.net/3206206202209204/Bubbles-Spheres-I-by-Peter-Sloterdijk.pdf
    • http://xiixmcuin.linkpc.net/7206209203205/Critique-of-Cynical-Reason-by-Peter-Sloterdijk.pdf
    • http://xiixmcuin.linkpc.net/1200203208206205209/Morte-aparente-no-pensamento-by-Peter-Sloterdijk.pdf
    • http://xiixmcuin.linkpc.net/8202200204209204/The-Bones-Of-St-Peter-A-Fascinating-Account-Of-The-Search-For-The-Apostle-s-Body-by-John-Evangelist-Walsh.pdf
    • http://xiixmcuin.linkpc.net/8200207204205204/The-Apostle-Paul-How-Did-the-Great-Apostle-endure-Persecutions-Abuse-and-Other-Great-Trials-by-Michael-Caputo.pdf
    • http://xiixmcuin.linkpc.net/5201204202208209/Nietzsche-The-Ethics-of-an-Immoralist-by-Peter-Berkowitz.pdf
    • http://xiixmcuin.linkpc.net/1200206209203201201/Nietzsche-s-Postmoralism-Essays-on-Nietzsche-s-Prelude-to-Philosophy-s-Future-by-Richard-Schacht.pdf
    • http://xiixmcuin.linkpc.net/7200203203206202/The-Gay-Science---Nietzsche-s-Forging-Metaphysical-Thought-by-Friedrich-Nietzsche.pdf
    • http://xiixmcuin.linkpc.net/2202202201203209/Basic-Writings-of-Nietzsche-by-Friedrich-Nietzsche.pdf
    • http://xiixmcuin.linkpc.net/6208206205205209/The-Case-of-Wagner-Nietzsche-Contra-Wagner-Selected-Aphorisms-by-Friedrich-Nietzsche.pdf
    • http://xiixmcuin.linkpc.net/6200209204201207/Spurs-Nietzsche-s-Styles-Eperons-Les-Styles-de-Nietzsche-by-Jacques-Derrida.pdf
    • http://xiixmcuin.linkpc.net/1200203208205206203/Sloterdijk-y-Heidegger-by-Carla-Cordua.pdf
    • http://xiixmcuin.linkpc.net/2202201201207203/Apostle-Rising-by-Richard-Godwin.pdf
    • http://xiixmcuin.linkpc.net/8202206204205201/Angel-and-Apostle-by-Deborah-Noyes.pdf
    • http://xiixmcuin.linkpc.net/2204203201203200/Apostle-of-the-Tyrants-by-Anthony-Hulse.pdf
    • http://xiixmcuin.linkpc.net/2203203208206202/The-Last-Apostle-John-the-Immortal-1-by-Dennis-Brooke.pdf