Malicious PDF — malware analysis report

Static analysis result for SHA-256 45dcc6138de081be…

MALICIOUS

PDF

19.0 KB Created: 2019-04-30 02:07:51 +01:00 Authoring application: mPDF 5.7
MD5: 2d972d90eafd3e8e1432408b8f30c6e5 SHA-1: 4f20d25fc9fc8fe999c411c250e2be2eeda3df17 SHA-256: 45dcc6138de081be2c9b8adead841b25fbf159dd7318aca89748215998a115ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is unreadable, the presence of numerous links suggests a social engineering tactic to direct users to malicious websites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201202205203207200/Man-Magnet-How-to-Be-the-Best-Woman-You-Can-Be-in-Order-to-Get-the-Best-Man-by-Romy-Miller.pdf
    • http://xiixmcuin.linkpc.net/3208207200206205/Saint-Leibowitz-and-the-Wild-Horse-Woman-by-Walter-M-Miller-Jr-.pdf
    • http://xiixmcuin.linkpc.net/7207201205203201/Dana-Stabenow-Books-Checklist-Reading-Order-Of-Coast-Guard-Series-in-Order-Kate-Shugak-Series-in-Order-Silk-and-Song-Trilogy-Star-Svensdotter-Series-in-Order-and-List-of-All-Dana-Stabenow-Books-by-Kevin-Hanson.pdf
    • http://xiixmcuin.linkpc.net/2209206203207208/Bonnet-Strings-An-Amish-Woman-s-Ties-to-Two-Worlds-by-Saloma-Miller-Furlong.pdf
    • http://xiixmcuin.linkpc.net/4204204200203209/Lousy-Magnet-by-Sally-Max.pdf
    • http://xiixmcuin.linkpc.net/8207208204201204/The-Wiener-Dog-Magnet-by-Hayes-Roberts.pdf
    • http://xiixmcuin.linkpc.net/1201202204208200/Geek-Magnet-by-Kieran-Scott.pdf
    • http://xiixmcuin.linkpc.net/9207201201204202/Modern-Sex-Liberation-And-Its-Discontents-by-Myron-Magnet.pdf
    • http://xiixmcuin.linkpc.net/3201200204205208/The-Bro-Magnet-Nice-Guy-1-by-Lauren-Baratz-Logsted.pdf
    • http://xiixmcuin.linkpc.net/2209208203208208/Calvin-Coconut-Trouble-Magnet-by-Graham-Salisbury.pdf
    • http://xiixmcuin.linkpc.net/6205204203206208/Aesthetic-Order-A-Philosophy-of-Order-Beauty-and-Art-by-Ruth-Lorand.pdf
    • http://xiixmcuin.linkpc.net/8202208205209202/Dennis-Lehane-Books-2017-Checklist-and-Reading-Order-The-Kenzie-Gennaro-Series-in-Order-Coughlin-Series-in-Order-and-List-of-All-Dennis-Lehane-Books-by-Thriller-Junkies.pdf
    • http://xiixmcuin.linkpc.net/1200207208202204/Floundering-by-Romy-Ash.pdf
    • http://xiixmcuin.linkpc.net/1200205207209209208/Watcher-by-Diana-Romy.pdf
    • http://xiixmcuin.linkpc.net/9201201207205202/Romy-in-Rom-z-rtliche-Blicke-by-Eva-Sereny.pdf
    • http://xiixmcuin.linkpc.net/1201202205203202204/Prohibited-Passion-by-Romy-Sommer.pdf
    • http://xiixmcuin.linkpc.net/1201202205203201208/Romy-Schneider-Story-by-Carolyn-Mcgivern.pdf
    • http://xiixmcuin.linkpc.net/1203203204203207/Snow-Flurries-and-Other-Stories-by-Romy-F-lck.pdf
    • http://xiixmcuin.linkpc.net/1201202205203203206/Romy-Bright-Crystal-Bay-Girls-2-by-Jen-Storer.pdf
    • http://xiixmcuin.linkpc.net/7204208202200201/DIE-LOSUNG-Mouches-volantes-by-Chantal-Romy.pdf
    • http://xiixmcuin.linkpc.net/12012022