Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fcb83448509e473…

MALICIOUS

PDF

22.1 KB Created: 2019-04-30 04:31:52 +01:00 Authoring application: mPDF 5.7
MD5: 3845b542d358cfb8c1f30bb8090df953 SHA-1: b51b81b1f22969289a5661f649fe38716cc8bf6d SHA-256: 1fcb83448509e47301357684c1553c6243eea71db80c5bbbec33dbbeff9ef807
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or traffic distribution scheme. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the document. While no scripts were extracted, the sheer volume of links and the ML classification indicate a high likelihood of malicious intent, possibly to distribute further malware or engage in SEO manipulation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/9208201208208207/The-Angel-Chronicles-Vol-5-Salvation---The-Final-Battle-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/9208201208209201/The-Angel-Chronicles-2nd-Edition-Volume-2-Guardians-of-the-Soul-The-Battle-for-Man-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/9208201208209206/The-Angel-Chronicles-Vol-3-Revenge-Of-The-Fallen-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/9208201208208209/The-Angel-Chronicles-Special-Edition-Volumes-1-5-w-Illustrations-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/9208201207209201/Ascend-A-Collection-Of-Contemporary-Urban-Poems-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/9208201208209204/The-Consumer-Value-Model-Know-The-Perceived-Value-of-Your-Products-amp-Services-and-Convert-Inquiries-Into-Purchases-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/9208201208208205/The-Globalization-Paradigm-The-Impact-of-Globalization-on-Industry-Consolidation-through-Mergers-amp-Acquisitions-by-Lanze-Thompson.pdf
    • http://xiixmcuin.linkpc.net/7207201204201/Battle-Angel-Alita-Volume-03-Killing-Angel-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/7207208205203/Battle-Angel-Alita-Volume-04-Angel-of-Victory-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/1200202204209203204/Battle-Angel-Alita---Last-Order-Angel-Cake-Vol-11-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/1200202204208206208/Battle-Angel-Alita---Last-Order-Angel-of-the-Innocents-Vol-02-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/7209206208204/Battle-Angel-Alita-Volume-07-Angel-Of-Chaos-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/1200202204209203201/Battle-Angel-Alita---Last-Order-Angel-s-Duty-Vol-09-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/8200202205202/Battle-Angel-Alita-Volume-08-Fallen-Angel-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/1202204208204205/Salvation-Guardian-Angel-3-by-Skyla-Madi.pdf
    • http://xiixmcuin.linkpc.net/6206209208207201/Battles-Involving-Hanover-Battle-of-Waterloo-Battle-of-Dettingen-Battle-of-Fontenoy-Battle-of-Tourcoing-Battle-of-Melle-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/3200209209203208/Serena-Reborn-The-Final-Battle-The-Wood-Sprite-Series-3-by-Lachelle-Redd.pdf
    • http://xiixmcuin.linkpc.net/1200202205200200208/Battle-Angel-Alita---Last-Order-Vol-17-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/5202203203209208/The-Chronicles-Of-Narnia-The-Magician-s-Nephew-The-Lion-The-Witch-and-The-Wardrobe-The-Horse-and-His-Boy-Prince-Caspian-The-Voyage-of-The-Dawn-Treader-The-Silver-Chair-The-Last-Battle-The-Chronicles-of-Narnia-1-7-by-C-S-Lewis.pdf
    • http://xiixmcuin.linkpc.net/1200202205201202200/Battle-Angel-Alita-Last-Order-Omnibus-3-by-Yukito-Kishiro.pdf
    • http://xiixmcuin.linkpc.net/9208201208209204/The-Consumer-Value-Model-Know-The-Perceived-Value-of-Your-Products-amp-Services-and-Con