Malicious PDF — malware analysis report

Static analysis result for SHA-256 39aec7de90a0ce86…

MALICIOUS

PDF

18.2 KB Created: 2019-04-30 04:07:17 +01:00 Authoring application: mPDF 5.7
MD5: 9ef1e3a0adbf5e3aab3facf6bae2e742 SHA-1: 5ba00cede5c02d1390169c1eb6c52eac23e01755 SHA-256: 39aec7de90a0ce862d7d2b0331118d3334eadb23e8aaa086c38ef490d1b2b471
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files. While many of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin
    • http://xiixmcuin.linkpc.net/6209209205209205/Marker-Magic-The-Rendering-Problem-Solver-for-Designers-by-Richard-M-McGarry.pdf
    • http://xiixmcuin.linkpc.net/1201203200206209207/The-Family-Tree-Problem-Solver-by-Marsha-Hoffman-Rising.pdf
    • http://xiixmcuin.linkpc.net/6205206204205209/1001-Solutions-to-Everyday-Problems-The-Practical-Problem-Solver-by-Earl-Proulx.pdf
    • http://xiixmcuin.linkpc.net/8206206207202200/The-Parrot-Problem-Solver-Finding-Solutions-to-Aggressive-Behavior-by-Barbara-Heidenreich.pdf
    • http://xiixmcuin.linkpc.net/6205206203209207/Yankee-s-Practical-Problem-Solver-1001-Ingenious-Solutions-to-Everyday-Dilemmas-by-Earl-Proulx.pdf
    • http://xiixmcuin.linkpc.net/3203200202206200/Problem-Solver-An-Amazing-Way-to-Deal-with-Problems-and-Personal-Challenges-Best-Business-Books-Book-10-by-Jonas-Stark.pdf
    • http://xiixmcuin.linkpc.net/5208208204208204/Borland-C-Builder-the-Definitive-C-Builder-Problem-Solver-by-John-Miano.pdf
    • http://xiixmcuin.linkpc.net/8202201206204207/Teaching-English-as-a-Second-Language-Giving-New-Learners-an-Everyday-Grammar-by-Richard-McGarry.pdf
    • http://xiixmcuin.linkpc.net/6209209205209203/Chris-Marker-Passengers-by-Chris-Marker.pdf
    • http://xiixmcuin.linkpc.net/1200209201206/That-Old-Cape-Magic-by-Richard-Russo.pdf
    • http://xiixmcuin.linkpc.net/1200206206204204202/Mardi-Gras-Magic-by-Remy-Richard.pdf
    • http://xiixmcuin.linkpc.net/5208202209202200/The-Structure-of-Magic-2-Volumes-by-Richard-Bandler.pdf
    • http://xiixmcuin.linkpc.net/1205208204201206/The-Magic-Goes-Away-Collection-The-Magic-Goes-Away-The-Magic-May-Return-More-Magic-by-Larry-Niven.pdf
    • http://xiixmcuin.linkpc.net/5205209202205208/Gilgamesh-A-New-Rendering-in-English-Verse-by-Anonymous.pdf
    • http://xiixmcuin.linkpc.net/2201208202200/Gilgamesh-A-New-Rendering-in-English-Verse-by-David-Ferry.pdf
    • http://xiixmcuin.linkpc.net/2209202209204206/The-Mahabharata-A-Modern-Rendering-2-Volumes-by-Ramesh-Menon.pdf
    • http://xiixmcuin.linkpc.net/2207205204201200/Rendering-Unto-Caesar-Was-Jesus-a-Socialist-by-Lawrence-W-Reed.pdf
    • http://xiixmcuin.linkpc.net/6209209206200200/The-Grave-Marker-by-Don-LaCroix.pdf
    • http://xiixmcuin.linkpc.net/6209209205200208/The-Marker-The-Bridge-1-by-Ann-Howes.pdf
    • http://xiixmcuin.linkpc.net/7206207206209202/Arabic-for-Designers-by-Mourad-Boutros.pdf