Malicious PDF — malware analysis report

Static analysis result for SHA-256 00d952c7fe16e95e…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 04:06:51 +01:00 Authoring application: mPDF 5.7
MD5: 2fe98052983bcacd053bb8639b744ba3 SHA-1: 09c1dba530c9cf44bd68f9c454acb50be5e15c4f SHA-256: 00d952c7fe16e95e0a396acd84772796f4f856ba3e5708eaf8eea5bddf1b1859
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness, and the PDF structure itself is flagged as a link farm. While no scripts were extracted, the sheer volume of links suggests a malicious intent to redirect the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/6205201204205/Bedbug-s-Writing-A-Collection-of-Short-Stories-Poetry-Volume-One-by-Tony-Lovell.pdf
    • http://xiixmcuin.linkpc.net/4205208205207209/When-Light-Fades-A-Collection-of-the-Darkest-Short-Stories-and-Poetry-by-Tabetha-Jones.pdf
    • http://xiixmcuin.linkpc.net/4205207206204207/Misery-Loves-Company-A-Collection-of-Dark-Short-Stories-and-Poetry-by-Misty-Burke.pdf
    • http://xiixmcuin.linkpc.net/2203201207206209/Darkness-Calls-A-Collection-of-Short-Stories---Volume-One-by-Andy-Hill.pdf
    • http://xiixmcuin.linkpc.net/1206205208203201/Life-Goes-On-Volume-1-A-Collection-of-Short-Stories-amp-Poems-by-Elizabeth-Riggin.pdf
    • http://xiixmcuin.linkpc.net/2206209209204203/Lies-I-Never-Told---A-Short-Collection-of-Short-Stories-by-Martin-Crosbie.pdf
    • http://xiixmcuin.linkpc.net/9209207207208204/Montauk-is-a-collection-of-haiku-and-short-poetry-by-W-D-Akin.pdf
    • http://xiixmcuin.linkpc.net/3202209201201202/Short-And-Simple-A-Collection-of-Short-Stories-by-R-L-Jones.pdf
    • http://xiixmcuin.linkpc.net/3201203206205200/Cute-Stories-for-Boys-amp-Girls-Hilarious-Collection-of-Short-Stories-by-Betty-J-Byers.pdf
    • http://xiixmcuin.linkpc.net/1201209202204201209/A-Suspicious-Collection-Of-Stories-Poetry-and-Drawings-by-Yen-Ooi.pdf
    • http://xiixmcuin.linkpc.net/4204206205200200/Writing-Poetry-to-Save-Your-Life-How-to-Find-the-Courage-to-Tell-Your-Stories-by-Maria-Mazziotti-Gillan.pdf
    • http://xiixmcuin.linkpc.net/2209205209206202/Sex-and-Stupidity-A-collection-of-Short-Stories-by-K-Syrah.pdf
    • http://xiixmcuin.linkpc.net/4205209203203203/Partial-Eclipse-A-Book-of-Poetry-Vassar-Miller-Prize-in-Poetry-1-by-Tony-Sanders.pdf
    • http://xiixmcuin.linkpc.net/3203202202200209/No-Vacancies-A-Collection-of-Short-Stories-Vol-3-by-Lucien-Black.pdf
    • http://xiixmcuin.linkpc.net/2209208209207202/Silver-Spurs-A-Collection-of-Short-Stories-by-Lee-Crittenden.pdf
    • http://xiixmcuin.linkpc.net/2207203203200200/The-Lagoon-A-Collection-of-Short-Stories-by-Janet-Frame.pdf
    • http://xiixmcuin.linkpc.net/9201203207202/Wormwood-A-Collection-of-Short-Stories-by-Poppy-Z-Brite.pdf
    • http://xiixmcuin.linkpc.net/5206202203209208/Degrees-of-Elevation-Short-Stories-of-Contemporary-Appalachia-Appalachian-Writing-Series-by-Chris-Offutt.pdf
    • http://xiixmcuin.linkpc.net/2204202205204208/Afternoon-Delights-A-Collection-of-Hot-Short-Stories-by-Mickey-Miller.pdf
    • http://xiixmcuin.linkpc.net/8208205200205209/Ahead-of-Time-A-Collection-of-Short-Stories-by-Henry-Kuttner.pdf