Malicious PDF — malware analysis report

Static analysis result for SHA-256 305c23c70efdb69a…

MALICIOUS

PDF

14.0 KB Created: 2019-05-02 05:50:37 +01:00 Authoring application: mPDF 5.7
MD5: f05fd77e73695ec2bf0f92c115000cf3 SHA-1: a262d0b47914489173aea23756575288c654649f SHA-256: 305c23c70efdb69ae18ccfd06d44f0344f7b9c79a029990c55b60af696fab15b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDFs hosted on the domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm, often used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2209205209206208/Her-Wyoming-Man-by-Cheryl-St-John.pdf
    • http://xiixmcuin.linkpc.net/1209205202203200/Wyoming-Tough-Wyoming-Men-1-by-Diana-Palmer.pdf
    • http://xiixmcuin.linkpc.net/2205205208203/Wyoming-Brave-Wyoming-Men-6-by-Diana-Palmer.pdf
    • http://xiixmcuin.linkpc.net/1200201200206204205/Donnelly-s-Promise-by-Cheryl-St-John.pdf
    • http://xiixmcuin.linkpc.net/2203203209201208/Want-Ad-Wedding-Cowboy-Creek-1-by-Cheryl-St-John.pdf
    • http://xiixmcuin.linkpc.net/3207203200206203/Western-Winter-Wedding-Bells-by-Cheryl-St-John.pdf
    • http://xiixmcuin.linkpc.net/2207205202206206/Writing-with-Emotion-Tension-and-Conflict-Techniques-for-Crafting-an-Expressive-and-Compelling-Novel-by-Cheryl-St-John.pdf
    • http://xiixmcuin.linkpc.net/7208200202203/Cheryl-My-Story-by-Cheryl-Cole.pdf
    • http://xiixmcuin.linkpc.net/9203200201202202/Wyoming-by-Rachael-Hanel.pdf
    • http://xiixmcuin.linkpc.net/4209200204205207/Miss-Wyoming-by-Douglas-Coupland.pdf
    • http://xiixmcuin.linkpc.net/2201201201206/Wyoming-Wedding-by-Barbara-McMahon.pdf
    • http://xiixmcuin.linkpc.net/2200207201207/Wyoming-Wildfire-by-Elizabeth-Lane.pdf
    • http://xiixmcuin.linkpc.net/9203201202207204/Wyoming-Manhunt-by-Ann-Voss-Peterson.pdf
    • http://xiixmcuin.linkpc.net/1203205204202200/Bad-Dirt-Wyoming-Stories-2-by-Annie-Proulx.pdf
    • http://xiixmcuin.linkpc.net/3207204205209201/A-Snowy-Christmas-in-Wyoming-Creeds-Crossing-1-by-E-Ayers.pdf
    • http://xiixmcuin.linkpc.net/1202203206207/The-Horse-Soldier-Garrett-s-of-Wyoming-1-by-Merline-Lovelace.pdf
    • http://xiixmcuin.linkpc.net/9207206209200207/Drinking-Dry-Clouds-Stories-From-Wyoming-by-Gretel-Ehrlich.pdf
    • http://xiixmcuin.linkpc.net/7206202209204/Green-Grass-of-Wyoming-Flicka-3-by-Mary-O-39-Hara.pdf
    • http://xiixmcuin.linkpc.net/1207209206206203/Open-Season-Liberty-Springs-Wyoming-4-by-Kaliana-Cole.pdf
    • http://xiixmcuin.linkpc.net/5209200204207205/Wed-In-Wyoming-Silhouette-Special-Edition-1833-by-Allison-Leigh.pdf
    • http://xiixmcuin.linkpc.net/220020720