Malicious PDF — malware analysis report

Static analysis result for SHA-256 40ef17ae7848b8e7…

MALICIOUS

PDF

29.7 KB Created: 2019-04-30 05:20:24 +01:00 Authoring application: mPDF 5.7
MD5: e6cbac9b9675d405dc6a45b9f53f048d SHA-1: cb9a07d13d86dc7ddaf2a7b6246f26d48ce18dd0 SHA-256: 40ef17ae7848b8e74db841b3d6997ebd602b04cabf44372451ffcd0210fd468e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, all hosted on the dynamic DNS domain 'xiixmcuin.linkpc.net'. This pattern is indicative of SEO poisoning or a link farm designed to drive traffic. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9885

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc
    • http://xiixmcuin.linkpc.net/5205205203203200/HUNGER-GAMES-MOVIE-QUIZ-for-Kids-Trivia-for-Kids-Book-1-by-Todd-J-Brock.pdf
    • http://xiixmcuin.linkpc.net/5205205203203204/Sleepover-Unofficial-Jennifer-Lawrence-Trivia-Games-What-is-your-Hunger-Games-IQ-Book-1-by-A-M-Rice.pdf
    • http://xiixmcuin.linkpc.net/5205205202205203/Hunger-Games-A-Detailed-Summary-of-Hunger-Games-Book-1----Along-With-Analysis-And-Fun-Quizes-Hunger-Games-Hunger-Games-Trilogy-Hunger-by-Mr-Summary.pdf
    • http://xiixmcuin.linkpc.net/4207201205200207/Dangerous-Animals-Of-The-Amazon---Interactive-Quiz-Book-For-Kids-Aged-9-to-12-by-Samantha-Flores.pdf
    • http://xiixmcuin.linkpc.net/4207201205209204/Who-is-the-King-of-Dinosaurs---Fun-Fact-Dinosaur-Quiz-book-for-Kids-aged-9-to-12-by-Samantha-Flores.pdf
    • http://xiixmcuin.linkpc.net/3201202207207201/Books-for-Kids-Super-Ants-Illustration-Book-kids-books-Ages-3-8-Bedtime-Stories-For-Kids-Children-s-Books-beginner-reader-books-Bugs-amp-Spiders-1-by-Robot-J-.pdf
    • http://xiixmcuin.linkpc.net/3201202203208202/Books-for-Kids-Tommy-Tiger-Becomes-a-Firefighter-Illustration-Book-Ages-3-8-Short-Stories-for-Kids-Kids-Books-Bedtime-Stories-For-Kids-Children-Books-Early-Readers-by-Tommy-Tiger.pdf
    • http://xiixmcuin.linkpc.net/5205204205206206/101-Movies-to-See-Before-You-Grow-Up-Be-your-own-movie-critic--the-must-see-movie-list-for-kids-by-Suzette-Valle.pdf
    • http://xiixmcuin.linkpc.net/8207206208209202/The-Everything-Kids-Math-Puzzles-Book-Brain-Teasers-Games-and-Activities-for-Hours-of-Fun-by-Meg-Clemens.pdf
    • http://xiixmcuin.linkpc.net/1208205201207209/Mathematics-Quiz-For-Kids-Multiplication-and-Division-by-Jane-April.pdf
    • http://xiixmcuin.linkpc.net/3206202202203/The-Hunger-Games-Official-Illustrated-Movie-Companion-by-Kate-Egan.pdf
    • http://xiixmcuin.linkpc.net/3201203207200208/Stories-For-Kids-amp-Teens-Includes-16-Original-Stories-with-Covers-Funny-Kids-Stories-Childrens-Book-Bundle-Animals-Character-Building-Lessons-by-Betty-J-Byers.pdf
    • http://xiixmcuin.linkpc.net/5206208204206205/102-ESL-Games-and-Activities-for-Kids-ESL-Activities-for-Children-ESL-Resources-for-New-and-Prospective-Teachers-Book-3-by-Miles-Jaworski.pdf
    • http://xiixmcuin.linkpc.net/9207207205206205/Soccer-For-Kids-Discover-the-Incredible-History-Fantastic-Facts-and-Amazing-Photos-of-the-World-s-Most-Popular-Sport-A-Children-s-Sport-Book-for-Ages-6-to-10-Soccer-Books-for-Kids-by-Lexington-Nabb.pdf
    • http://xiixmcuin.linkpc.net/3201203203207202/Halloween-Stories-for-Kids-amp-More-17-Assorted-Stories-to-Read-with-Kids-at-Halloween-Bonus-Halloween-Party-Story-Kids-Story-Bundle-Children-s-Series-Spooky-Scary-Funny-by-Betty-J-Byers.pdf
    • http://xiixmcuin.linkpc.net/1201203204201206203/Kids-Still-Having-Kids-Talking-About-Teen-Pregnancy-Impact-Books-by-Janet-Bode.pdf
    • http://xiixmcuin.linkpc.net/1201201204207204/The-Vanishings-Four-Kids-Face-Earth-s-Last-Days-Together-Left-Behind-The-Kids-1-by-Jerry-B-Jenkins.pdf
    • http://xiixmcuin.linkpc.net/1201203200201209200/250-Fun-Jokes-for-Kids-Joke-Books-for-Kids-by-Joe-King.pdf
    • http://xiixmcuin.linkpc.net/1200200207208208209/What-Kids-Buy-and-Why-The-Psychology-of-Marketing-to-Kids-by-Daniel-Acuff.pdf
    • http://xiixmcuin.linkpc.net/3202202206200/The-Hunger-Games-Trilogy-Boxset-The-Hunger-Games-1-3-by-Suzanne-Collins.pdf