Malicious PDF — malware analysis report

Static analysis result for SHA-256 3356bb44e51ef070…

MALICIOUS

PDF

14.4 KB Created: 2019-04-30 19:13:02 +01:00 Authoring application: mPDF 5.7
MD5: eb2891d9a1847dabf03113c0ca58e389 SHA-1: 916ced567426d2ac0e11ce3012366b4cdf2ddfa7 SHA-256: 3356bb44e51ef070982702fbc9e372cf95056c8eaae541d45eccdd71dcfb5e27
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a "PDF_SEO_LINK_FARM" attack pattern, suggesting the document's purpose is to drive traffic to these external links. While the URLs themselves are marked as benign, the sheer volume and structure point to a malicious intent to manipulate search engine results or distribute content through a link farm. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9200

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3205207202200205/Hawk-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/2201208206203205/Agyar-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/2208202206204201/The-Sun-the-Moon-amp-the-Stars-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/2207205206206202/Hawk-Vlad-Taltos-14-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/3202207203205201/Iorich-Vlad-Taltos-12-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/2205202207205202/Iorich-Vlad-Taltos-12-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/8208207203209201/Steven-Brust-s-Jhereg---The-Graphic-Novel-by-Alan-Zelenetz.pdf
    • http://xiixmcuin.linkpc.net/3202206203202201/The-Book-of-Athyra-Vlad-Taltos-6-7-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/3200206207204202/Cowboy-Feng-s-Space-Bar-and-Grille-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/1205205209209200/The-Paths-of-the-Dead-Khaavren-Romances-3-The-Viscount-of-Adrilankha-1-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/8203205205201/Taltos-Vlad-Taltos-4-by-Steven-Brust.pdf
    • http://xiixmcuin.linkpc.net/9208202207204201/Kangaroos-by-Beth-Wagner-Brust.pdf
    • http://xiixmcuin.linkpc.net/9208202207203208/Rattlesnakes-Zoobooks-by-Beth-Wagner-Brust.pdf
    • http://xiixmcuin.linkpc.net/9208202207200200/Zwei-Seelen-in-der-Brust-by-Vera-Vieli.pdf
    • http://xiixmcuin.linkpc.net/9208202206209202/Brust-oder-Flasche-by-Livia-G-rner.pdf
    • http://xiixmcuin.linkpc.net/9208202207209203/Der-Feind-in-der-Brust-meiner-Frau-by-J-rgen-Remm.pdf
    • http://xiixmcuin.linkpc.net/9208202207203207/Programming-Microsoft-SQL-Server-2005-by-Andrew-J-Brust.pdf
    • http://xiixmcuin.linkpc.net/9208202207203209/Great-Molasses-Flood-by-Beth-Wagner-Brust.pdf
    • http://xiixmcuin.linkpc.net/9208202206209207/Where-Custer-Fell-Photographs-of-the-Little-Bighorn-Battlefield-Then-and-Now-by-James-S-Brust.pdf
    • http://xiixmcuin.linkpc.net/6209206204203205/Steven-Gerrard-My-Liverpool-Story-by-Steven-Gerrard.pdf
    • http://xiixmcuin.linkpc.net/9208202207204