Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a7eca3c75f8ed01…

MALICIOUS

PDF

19.4 KB Created: 2019-05-02 17:48:55 +01:00 Authoring application: mPDF 5.7
MD5: 107fdde27ec2b5b8f7cd5a5d58400f08 SHA-1: 14768babba429b95fba4c51ddde776a517b63224 SHA-256: 2a7eca3c75f8ed015d1ef758292f265d4f373fead6af6052e2f79ed28080e75f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain xiixmcuin.linkpc.net. This pattern is indicative of a link farm or a phishing lure designed to direct users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5201201203207208/Activities-for-Interactive-Whiteboards-by-Daniel-Martin.pdf
    • http://xiixmcuin.linkpc.net/1200204203208204204/Essential-Mathematics-for-Games-and-Interactive-Applications-A-Programmer-s-Guide-The-Morgan-Kaufmann-Series-in-Interactive-3D-Technology-by-James-M-Van-Verth.pdf
    • http://xiixmcuin.linkpc.net/5206208204206205/102-ESL-Games-and-Activities-for-Kids-ESL-Activities-for-Children-ESL-Resources-for-New-and-Prospective-Teachers-Book-3-by-Miles-Jaworski.pdf
    • http://xiixmcuin.linkpc.net/7207207204203204/Anne-Of-Green-Gablesan-Interactive-Cd-Rom-Novel-Anne-La-Maison-Au-Pignons-Verts-Un-Roman-Interactif-Sur-Cd-Rom-by-Renaissance-Interactive-Studios.pdf
    • http://xiixmcuin.linkpc.net/3209208203208206/The-Champ-by-Daniel-Martin-Eckhart.pdf
    • http://xiixmcuin.linkpc.net/9201202201205200/Mysterium-Fidei-by-Daniel-Martin-Diaz.pdf
    • http://xiixmcuin.linkpc.net/3206209204204201/Talking-To-The-Sharks-Daniel-Jacquot-9-by-Martin-O-39-Brien.pdf
    • http://xiixmcuin.linkpc.net/3203202202203201/George-R-R-Martin-s-Wild-Cards-The-Hard-Call-by-Daniel-Abraham.pdf
    • http://xiixmcuin.linkpc.net/3208200202200202/Become-the-Woman-of-Your-Dreams-2-Interactive-Gender-Transformation-Feminization-Erotica-Aurora-Sparks-Interactive-Erotica-3-by-Aurora-Sparks.pdf
    • http://xiixmcuin.linkpc.net/3203202202201203/George-R-R-Martin-s-Wild-Cards-The-Hard-Call-Part-5-by-Daniel-Abraham.pdf
    • http://xiixmcuin.linkpc.net/4204206206200200/Jacquot-and-the-Fifteen-Daniel-Jacquot-4-by-Martin-O-39-Brien.pdf
    • http://xiixmcuin.linkpc.net/7204209206209208/The-Interactive-Stance-by-Jonathan-Ginzburg.pdf
    • http://xiixmcuin.linkpc.net/3207205203200206/A-Fun-Interactive-Psychological-Adventure-by-Damien-Darby.pdf
    • http://xiixmcuin.linkpc.net/1200209208207201205/Autumn-Activities-by-Denise-Bieniek.pdf
    • http://xiixmcuin.linkpc.net/8201201200201200/Trial-of-the-Clone-An-Interactive-Adventure-by-Zach-Weinersmith.pdf
    • http://xiixmcuin.linkpc.net/9200203206205207/Demigods-of-Olympus-An-Interactive-Adventure-by-Rick-Riordan.pdf
    • http://xiixmcuin.linkpc.net/7202202203203205/Microeconomics-Interactive-Software-Supplement-by-Jeff-Perloff.pdf
    • http://xiixmcuin.linkpc.net/2204206202202206/Wicked-Way-Interactive-1-Sex-Spies-and-Photographs-by-Daire-St-Denis.pdf
    • http://xiixmcuin.linkpc.net/6209204205204205/Interactive-French-Reader---Level-1-by-Philippe-Delannoy.pdf
    • http://xiixmcuin.linkpc.net/9209204209203205/52-Elf-Activities-to-Make-You-the-Best-Grandparent-by-David-Brisco.pdf
    • http://xiixmcuin.linkpc.net/72072072042032