Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d111aa5b1c36919…

MALICIOUS

PDF

18.2 KB Created: 2019-05-05 16:10:24 +01:00 Authoring application: mPDF 5.7
MD5: de3a5a7a92f21a74d8aadba917ac3d77 SHA-1: af084a09459c6f9d2d9a7e26535cf66dd358aa74 SHA-256: 3d111aa5b1c36919f3ca3faf36a2045c33696929ad07fe180d28a3ee2f792390
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a content-luring scheme, often used to distribute malicious content or drive traffic. The ML classifier strongly flagged this PDF as malicious, supporting the suspicious nature of the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4205202202209201/The-Erl-King-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/1206205202207201/Gemini-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200203207206/The-Four-Wise-Men-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200204204207/The-Wind-Spirit-An-Autobiography-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/6203205203200207/The-Education-Of-Robinson-Crusoe-A-Study-Of-Vendredi-Ou-La-Vie-Sauvage-By-Michel-Tournier-by-F-J-Fornasiero.pdf
    • http://xiixmcuin.linkpc.net/7207206202205205/Lettres-parl-es-son-ami-allemand-Hellmut-Waller-1967-1998-Hors-s-rie-Litt-rature-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/2200208203201208/The-King-Tingaling-Painting-Duke-amp-Michel-2-by-Elias-Zapple.pdf
    • http://xiixmcuin.linkpc.net/5205200203208203/To-Understand-Each-Other-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200204205206/Learn-to-Grow-Old-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200204205200/A-Place-for-You-Psychology-and-Religion-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200204205202/The-Whole-Person-in-a-Broken-World-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5209204201207201/Les-Pardaillan-Int-grale-les-10-Volumes-de-Michel-Z-vaco-French-Edition-by-Michel-Z-vaco.pdf
    • http://xiixmcuin.linkpc.net/5209203208201202/Oeuvres-de-Michel-Z-vaco-Borgia-les-Pardaillan-le-Pont-des-Soupirs-by-Michel-Z-vaco.pdf
    • http://xiixmcuin.linkpc.net/8200201204200201/18-ROMANS-DE-MICHEL-Z-VACO-en-version-int-grale-annot-e-by-Michel-Z-vaco.pdf
    • http://xiixmcuin.linkpc.net/6202208201208203/The-King-of-Trees-Three-Novellas-The-King-of-Trees-The-King-of-Chess-The-King-of-Children-by-Ah-Cheng.pdf
    • http://xiixmcuin.linkpc.net/7207208200203209/Michel-Roux-s-Finest-Desserts-by-Michel-Roux.pdf
    • http://xiixmcuin.linkpc.net/1200203200208204204/Technologies-of-the-Self-A-Seminar-with-Michel-Foucault-by-Michel-Foucault.pdf
    • http://xiixmcuin.linkpc.net/1200203208201205201/Foucault-Blanchot-Maurice-Blanchot-The-Thought-from-Outside-amp-Michel-Foucault-as-I-Imagine-Him-by-Michel-Foucault.pdf
    • http://xiixmcuin.linkpc.net/2204201209201/King-of-the-Comics-One-Hundred-Years-of-King-Features-Syndicate-by-Dean-Mullaney.pdf
    • http://xiixmcuin.linkpc.net/4203204207206208/The-Vampire-King-The-Horn-King-Series-Book-3-by-Brae-Wyckoff.pdf
    • http://xiixmcuin.linkpc.net/5205200204205206/Learn-to-Grow-Ol