Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d136bee9dbf4ae6…

MALICIOUS

PDF

25.3 KB Created: 2019-05-02 18:32:08 +01:00 Authoring application: mPDF 5.7
MD5: 9c5825fefa2b6f1087aabccd6737e714 SHA-1: 09cd4dc968aff8967a306e99f8672cb4a8244bf6 SHA-256: 3d136bee9dbf4ae6ff1755d09daceceea98d163439aee7221085d25c6c8c19a4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a mass of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to numerous PDF files hosted on xiixmcuin.linkpc.net. While the linked PDFs themselves are marked as benign, the sheer volume and deceptive nature of the links suggest a malicious intent to drive traffic or potentially host malicious content indirectly. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8209202200204/The-Curious-Case-of-Benjamin-Button-and-Other-Jazz-Age-Stories-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/8201206209203206/The-Curious-Case-of-Benjamin-Button-and-Other-Tales-of-the-Jazz-Age-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/8202204207204200/THE-SHORT-STORIES-OF-F-SCOTT-FITZGERALD---A-New-Collection-Head-and-Shoulders-Bernice-Bobs-Her-Hair-The-Ice-Palace-The-Offshore-Pirate-May-Day-The-Jelly-Bean-The-Curious-Case-of-Benjamin-Button-The-Diamond-as-Big-as-the-Ritz-Winter-Dreams-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/7207202200201208/The-Curious-Case-of-Benjamin-Button-Brad-Pitt---Illustrated-with-movie-pictures---Francis-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/1201202205201207200/The-Curious-Case-of-Benjamin-Button-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/3207208205208203/The-Curious-Case-of-Benjamin-Button-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/8202204208207208/F-Scott-Fitzgerald-Four-Pack---Benjamin-Button-This-Side-of-Paradise-The-Beautiful-and-Damned-The-Diamond-as-big-as-The-Ritz-Illustrated-by-Norman-Rockwell-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/7204208207205207/F-Scott-Fitzgerald-Short-Stories-1921-to-1940-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/1209202208205206/Tales-of-the-Jazz-Age-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/4203200202207209/Six-Tales-of-the-Jazz-Age-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/5204203209201201/Before-Gatsby-The-First-Twenty-Six-Stories-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/1200208205200205201/Diamond-as-Big-as-the-Ritz-amp-Other-Stories-Oper-5-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/5202205202205201/This-Side-of-Paradise-Is-the-Debut-Novel-by-F-Scott-Fitzgerald-original-Classic-By-Rupert-Brooke-3-August-1887---23-April-1915-Was-an-English-Poet-and-by-Oscar-Wilde-16-October-1854---30-November-1900-Was-an-Irish-Playwright-Novelist-Essayist-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/7207200207200200/This-Side-of-Paradise-1920-by-F-Scott-Fitzgerald-This-Side-of-Paradise-Is-the-Debut-Novel-by-F-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/9206207201209/The-Complete-Works-of-F-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://xiixmcuin.linkpc.net/1200205201206203206/Fool-for-Love-F-Scott-Fitzgerald-by-Scott-Donaldson.pdf
    • http://xiixmcuin.linkpc.net/4209200203201206/The-Three-Button-Trick-and-Other-Stories-by-Nicola-Barker.pdf
    • http://xiixmcuin.linkpc.net/4203204208206204/Button-Holed-Button-Box-Mystery-1-by-Kylie-Logan.pdf
    • http://xiixmcuin.linkpc.net/1201207200203206/The-Jazz-by-Melissa-Scott.pdf
    • http://xiixmcuin.linkpc.net/3204209200207208/The-Man-From-U-N-D-E-A-D---The-Curious-Case-Of-The-Kidnapped-Chemist-by-Darren-Humphries.pdf