Malicious PDF — malware analysis report

Static analysis result for SHA-256 26742ca363555ba1…

MALICIOUS

PDF

20.2 KB Created: 2019-05-01 17:51:03 +01:00 Authoring application: mPDF 5.7
MD5: 1de3b6fd8bfc874e173fe71980e47994 SHA-1: 66fbdfbf71c2daf65acf2db142d3974506662c37 SHA-256: 26742ca363555ba180b28b62d84d7232f08a9ac04b59c689ce0c82c3e21d549e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear to point to benign book titles, the sheer volume and the use of a dynamic DNS hostname (linkpc.net) suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2206202203208208/Moments-of-Truth-Twelve-Twentieth-Century-Women-Writers-by-Lorna-Sage.pdf
    • http://xiixmcuin.linkpc.net/1200202201209202203/The-Twentieth-Century-in-100-Moments-A-Visual-History-by-Akim-D-Reinhardt.pdf
    • http://xiixmcuin.linkpc.net/3208205206208209/The-Oxford-History-of-the-British-Empire-Volume-IV-The-Twentieth-Century-Twentieth-Century-Vol-4-by-Judith-M-Brown.pdf
    • http://xiixmcuin.linkpc.net/1201200200207208206/Twentieth-Century-Women-Poems-by-Arthur-Vogelsang.pdf
    • http://xiixmcuin.linkpc.net/5201206205206204/Texas-Through-Women-s-Eyes-The-Twentieth-Century-Experience-by-Judith-N-McArthur.pdf
    • http://xiixmcuin.linkpc.net/2203208202202209/Bachelor-Girl-The-Secret-History-of-Single-Women-in-the-Twentieth-Century-by-Betsy-Israel.pdf
    • http://xiixmcuin.linkpc.net/2202202204200201/The-Workshop-Seven-Decades-of-the-Iowa-Writers-Workshop---43-Stories-Recollections-amp-Essays-on-Iowa-s-Place-in-Twentieth-Century-American-Literature-by-Tom-Grimes.pdf
    • http://xiixmcuin.linkpc.net/1200204201209205/Bad-Blood-by-Lorna-Sage.pdf
    • http://xiixmcuin.linkpc.net/5207209200205202/The-Unmade-Bed-The-Messy-Truth-about-Men-and-Women-in-the-21st-Century-by-Stephen-Marche.pdf
    • http://xiixmcuin.linkpc.net/4207200203207205/Flesh-and-the-Mirror-Essays-on-the-Art-of-Angela-Carter-by-Lorna-Sage.pdf
    • http://xiixmcuin.linkpc.net/1201200202201200/Our-More-Perfect-Union-From-Eighteenth-Century-Principles-to-Twentieth-Century-Practice-by-Arthur-Norman-Holcombe.pdf
    • http://xiixmcuin.linkpc.net/4207208203205208/Women-Without-Superstition-No-Gods--No-Masters-The-Collected-Writings-of-Women-Freethinkers-of-the-Nineteenth-and-Twentieth-Centuries-by-Annie-L-Gaylor.pdf
    • http://xiixmcuin.linkpc.net/8206200202208204/Art-of-the-Twentieth-Century-by-Ingo-F-Walther.pdf
    • http://xiixmcuin.linkpc.net/4205207201205/From-the-End-of-the-Twentieth-Century-by-John-M-Ford.pdf
    • http://xiixmcuin.linkpc.net/1205204206208208/Paris-in-the-Twentieth-Century-by-Jules-Verne.pdf
    • http://xiixmcuin.linkpc.net/3202209202201202/Allergic-to-the-Twentieth-Century-by-Peter-Radetsky.pdf
    • http://xiixmcuin.linkpc.net/4204207204201201/The-Man-Who-Invented-the-Twentieth-Century-by-Robert-Lomas.pdf
    • http://xiixmcuin.linkpc.net/1205207208203/Other-Criteria-Confrontations-with-Twentieth-Century-Art-by-Leo-Steinberg.pdf
    • http://xiixmcuin.linkpc.net/9202203205205/In-Europe-Travels-Through-the-Twentieth-Century-by-Geert-Mak.pdf
    • http://xiixmcuin.linkpc.net/1200202200205202206/Saga-Into-the-Twentieth-Century-by-Louise-Haeger.pdf
    • http://xiixmcuin.linkpc.net/2202202204200201/The-Workshop-Seven-Decades-of-the-Iowa-Writers-Workshop---43-Stories-Recollections-amp-Essays-on-Iowa-s-Place-in-Twentieth-Centu