Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc024a586576dce9…

MALICIOUS

PDF

27.2 KB Created: 2019-05-04 13:13:14 +01:00 Authoring application: mPDF 5.7
MD5: eb6ebf2280a686c30b340371a27d96d1 SHA-1: 6340dbed4ae87e06100b4328262bfa31f618d122 SHA-256: fc024a586576dce906e27b70ea62673fcdc7cde8940675cf4b917aab9182a7ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zacdsa.linkpc.net/2c53c58c55c58c51/Judgment-of-Paris-California-vs-France-and-the-Historic-1976-Paris-Tasting-That-Revolutionized-Wine-by-George-M-Taber.pdf
    • http://zacdsa.linkpc.net/7c59c56c50c58c55/Schienenverkehr-Paris-Bahnhof-in-Paris-Metro-Paris-Strassenbahn-Paris-Metrolinie-7bis-Chemin-de-Fer-de-Petite-Ceinture-Ratp-by-Quelle-Wikipedia.pdf
    • http://zacdsa.linkpc.net/5c54c54c51c55c56/Journal-Paris-France-Personal-Journal-by-Aprilynne-Paris.pdf
    • http://zacdsa.linkpc.net/1c50c53c54c55c57c57/Bahnhof-in-Frankreich-Bahnhof-in-Paris-Rer-Bahnhof-Ile-de-France-Bahnhof-Strasbourg-Bahnhof-Metz-Gare-Montparnasse-Paris-Gare-Du-Nord-by-Quelle-Wikipedia.pdf
    • http://zacdsa.linkpc.net/4c54c55c50c50c52/Paris-France-by-Gertrude-Stein.pdf
    • http://zacdsa.linkpc.net/4c54c55c56c54c52/The-Golden-Moments-of-Paris-A-Guide-to-the-Paris-of-the-1920s-by-John-Baxter.pdf
    • http://zacdsa.linkpc.net/4c54c55c51c52c58/Walks-in-Hemingway-s-Paris-A-Guide-to-Paris-for-the-Literary-Traveler-by-No-l-Riley-Fitch.pdf
    • http://zacdsa.linkpc.net/8c56c55c58c50c50/Orpheus-in-Paris-Offenbach-and-the-Paris-of-His-Time-by-Siegfried-Kracauer.pdf
    • http://zacdsa.linkpc.net/8c50c54c55c51c57/How-Paris-Became-Paris-The-Invention-of-the-Modern-City-by-Joan-DeJean.pdf
    • http://zacdsa.linkpc.net/1c51c57c55c55c54/Paris-Paris-Journey-into-the-City-of-Light-by-David-Downie.pdf
    • http://zacdsa.linkpc.net/6c50c51c57c53/The-Glow-of-Paris-The-Bridges-of-Paris-at-Night-by-Gary-Zuercher.pdf
    • http://zacdsa.linkpc.net/5c52c59c55c53c52/When-Paris-Sizzled-The-1920s-Paris-of-Hemingway-Chanel-Cocteau-Cole-Porter-Josephine-Baker-and-Their-Friends-by-Mary-McAuliffe.pdf
    • http://zacdsa.linkpc.net/2c53c55c56c58c58/Down-and-Out-in-Paris-and-London-by-George-Orwell.pdf
    • http://zacdsa.linkpc.net/1c50c50c52/The-Little-Paris-Bookshop-by-Nina-George.pdf
    • http://zacdsa.linkpc.net/8c56c51c54c51c54/Erledigt-in-Paris-und-London-by-George-Orwell.pdf
    • http://zacdsa.linkpc.net/6c54c58c50c54c52/Homage-to-Catalonia-Down-and-Out-in-Paris-and-London-by-George-Orwell.pdf
    • http://zacdsa.linkpc.net/8c53c56c54c57c56/Nouvelles-Annales-de-Paris-Jusqu-au-Regne-de-Hugues-Capet-On-Y-Joint-Le-Po-me-d-Abbon-Sur-Le-Fameux-Si-ge-de-Paris-Par-Les-Normans-En-885-amp-886-Beaucoup-Plus-Correct-Que-Dans-Aucune-Des-ditions-Pr-c-d-ntes-by-Michel-Toussaint-Chretien-Duplessis.pdf
    • http://zacdsa.linkpc.net/6c57c59c52c55c58/Le-Paris-um-Ou-Tableau-Actuel-de-Paris-Ouvrage-Indispensable-Pour-Conna-tre-Et-Visiter-En-Peu-de-Temps-Ce-Qu-il-Y-a-de-Curieux-Dans-Cette-Capitale-Et-Aux-Environs-Antiquit-s-Edifices-Mus-es-Manufactures-Spectacles-On-Y-Trouvera-Les-Embellissem-by-J-Francois-C-Blanvillain.pdf
    • http://zacdsa.linkpc.net/4c58c50c59c59c58/The-Paris-Review-Interviews-II-Wisdom-from-the-World-s-Literary-Masters-by-The-Paris-Review.pdf
    • http://zacdsa.linkpc.net/1c50c51c52c54c57c56/Wine-A-Tasting-Course-by-Marnie-Old.pdf
    • http://zacdsa.linkpc.net/1c50c53c54c55c57c57/Bahnhof-in-Frankreich-Bahnhof-in-Paris-Rer-Bahnhof-Ile-de-France-Bahnhof-Strasbourg-Bahnhof-Metz-Ga