Malicious PDF — malware analysis report

Static analysis result for SHA-256 3aac56c0b783f04a…

MALICIOUS

PDF

16.2 KB Created: 2019-04-30 19:01:55 +01:00 Authoring application: mPDF 5.7
MD5: 1813bad323481be94edb035816618339 SHA-1: 29595b761d7e96c0bcbda0bc7eab2a78eb5a23ed SHA-256: 3aac56c0b783f04ac17dc7c28e15beb3a85115540ffda511900f0fec611a8a2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3206206200209209/Alluvial-Valos-of-Sonhadra-1-by-Amanda-Milo.pdf
    • http://xiixmcuin.linkpc.net/1200209206201208206/Tempest-Valos-of-Sonhadra-2-by-Poppy-Rhys.pdf
    • http://xiixmcuin.linkpc.net/3209207202203204/Blazing-Valos-of-Sonhadra-3-by-Nancey-Cummings.pdf
    • http://xiixmcuin.linkpc.net/3209207202203200/Radiant-Valos-of-Sonhadra-5-by-Naomi-Lucas.pdf
    • http://xiixmcuin.linkpc.net/5204206204204208/Iced-Valos-of-Sonhadra-10-by-Regine-Abel.pdf
    • http://xiixmcuin.linkpc.net/5205202208206203/Craved-by-an-Alien-Stolen-by-an-Alien-4-by-Amanda-Milo.pdf
    • http://xiixmcuin.linkpc.net/1204207203205200/Won-by-an-Alien-Stolen-by-an-Alien-3-by-Amanda-Milo.pdf
    • http://xiixmcuin.linkpc.net/8200204201208206/Milo-and-Kumo-and-The-Little-Chick-Milo-and-Kumo-s-Caribbean-Adventures-Book-1-by-Freyja-Gata.pdf
    • http://xiixmcuin.linkpc.net/5207201201201202/Milo-Manara-s-Odysseys-Of-Giuseppe-Bergman-by-Milo-Manara.pdf
    • http://xiixmcuin.linkpc.net/1204204208205201/Stolen-by-an-Alien-Stolen-by-an-Alien-1-by-Amanda-Milo.pdf
    • http://xiixmcuin.linkpc.net/1204207204207207/Stolen-by-an-Alien-Stolen-by-an-Alien-1-by-Amanda-Milo.pdf
    • http://xiixmcuin.linkpc.net/7206205207209205/Unraveled-The-Amanda-Project-4-by-Amanda-Valentino.pdf
    • http://xiixmcuin.linkpc.net/1202204209201200/Invisible-I-The-Amanda-Project-1-by-Amanda-Valentino.pdf
    • http://xiixmcuin.linkpc.net/1206202209202200/Amanda-Lester-and-the-Blue-Peacocks-Secret-Amanda-Lester-Detective-4-by-Paula-Berinstein.pdf
    • http://xiixmcuin.linkpc.net/1206202207206207/Amanda-Lester-and-the-Purple-Rainbow-Puzzle-Amanda-Lester-Detective-3-by-Paula-Berinstein.pdf
    • http://xiixmcuin.linkpc.net/1201208200207208206/Rendezvous-Ravished-Reckless-Amanda-Quick-Triple-Exclusive-by-Amanda-Quick.pdf
    • http://xiixmcuin.linkpc.net/5207201201204202/The-Paper-Man-by-Milo-Manara.pdf
    • http://xiixmcuin.linkpc.net/8200200208201204/Le-d-clic-T04-by-Milo-Manara.pdf
    • http://xiixmcuin.linkpc.net/8200200208201208/Le-d-clic-T02-by-Milo-Manara.pdf
    • http://xiixmcuin.linkpc.net/1204209209209206/Milo-s-Hat-Trick-by-Jon-Agee.pdf
    • http://xiixmcuin.linkpc.net/8200204201208206/Milo-and-Kumo-and-The-Little-Chick-Milo-and-Kumo-s-Caribbean-Adventures-Book-1-by-Freyja-