Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a9aaf723b835100…

MALICIOUS

PDF

17.5 KB Created: 2019-05-05 15:45:58 +01:00 Authoring application: mPDF 5.7
MD5: d47a9649778b759c8a86372b9a69c905 SHA-1: b25611752f8f3c9ae9d60a1c77a913d8d97b5bca SHA-256: 3a9aaf723b835100153b5c482e5a9d87eea23f461680985aaa89caa3b62d406e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used to obscure malicious intent or distribute further content. The ML classifier strongly indicated maliciousness, and the heuristic firing confirms the presence of a link farm hosted on the suspicious domain 'xiixmcuin.linkpc.net'. While no scripts were extracted, the sheer volume of links and the suspicious domain suggest a delivery mechanism for potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4207206206201204/The-Facts-of-Life-by-R-D-Laing.pdf
    • http://xiixmcuin.linkpc.net/6201205203202201/Facts-Of-Life-by-Pippo-Lionni.pdf
    • http://xiixmcuin.linkpc.net/6201205203207201/Facts-Of-Life-by-Pippi-Lionni.pdf
    • http://xiixmcuin.linkpc.net/7202203200208205/Patient-Drug-Facts-2004-Published-by-Facts-and-Comparisons-by-Timothy-R-Covington.pdf
    • http://xiixmcuin.linkpc.net/7201207207206205/Random-Facts-1869-Facts-To-Make-You-Want-To-Learn-More-by-Nazar-Shevchenko.pdf
    • http://xiixmcuin.linkpc.net/7203208203201207/Invincible-Vol-5-The-Facts-of-Life-by-Robert-Kirkman.pdf
    • http://xiixmcuin.linkpc.net/7207200201202208/Colorless-Tsukuru-Tazaki-and-His-Years-of-Pilgrimage---101-Book-Facts-1-Fun-Facts-amp-Trivia-Tidbits-by-G-Whiz.pdf
    • http://xiixmcuin.linkpc.net/7205204205203200/Americanah-by-Chimamanda-Ngozi-Adichie-Top-50-Facts-Coutndown-by-Top-50-Facts.pdf
    • http://xiixmcuin.linkpc.net/1209209207202203/The-Facts-of-Life-and-Other-Dirty-Jokes-by-Willie-Nelson.pdf
    • http://xiixmcuin.linkpc.net/8206202207208205/Creation-Facts-Of-Life-Revisited-Pb-by-Gary-E-Parker.pdf
    • http://xiixmcuin.linkpc.net/5202200202205204/The-New-Corporate-Facts-of-Life-Rethink-Your-Business-to-Transform-Today-s-Challeneges-Into-Tomorrow-s-Profits-by-Diana-Rivenburgh.pdf
    • http://xiixmcuin.linkpc.net/3201208209208209/Animal-Butts-amp-Facts-Too-Fun-Animal-Books-for-Kids-With-Facts-amp-Incredible-Photos-Exploring-Our-Incredible-World-Children-s-Book-Series-by-Mark-Smith.pdf
    • http://xiixmcuin.linkpc.net/2204202202209205/Self-and-Others-by-R-D-Laing.pdf
    • http://xiixmcuin.linkpc.net/7205208201201/The-Death-of-Innocence-by-Stuart-S-Laing.pdf
    • http://xiixmcuin.linkpc.net/6204205209208208/The-Whisky-River-by-Robin-Laing.pdf
    • http://xiixmcuin.linkpc.net/3208206207200206/The-Politics-of-the-Family-and-Other-Essays-by-R-D-Laing.pdf
    • http://xiixmcuin.linkpc.net/2205206204204206/The-Politics-of-Experience-The-Bird-of-Paradise-by-R-D-Laing.pdf
    • http://xiixmcuin.linkpc.net/2200209203201203/Doctor-Who-The-Official-Annual-2015-by-Moray-Laing.pdf
    • http://xiixmcuin.linkpc.net/9201202209202209/The-Absolution-of-Roberto-Acestes-Laing-by-Nicholas-Rombes.pdf
    • http://xiixmcuin.linkpc.net/4200207202202205/How-to-be-YOU-A-Winner-s-Guide-to-Self-Empowerment-by-David-Bennett-Laing.pdf
    • http://xiixmcuin.linkpc.net/7205204205203200/Americana