Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b9b946f5a3a29bf…

MALICIOUS

PDF

22.6 KB Created: 2019-05-07 03:59:48 +01:00 Authoring application: mPDF 5.7
MD5: f348e41429e4dd6187303a159be6d117 SHA-1: 316ce6257571ae997d04be2f8dde7d029a871e3e SHA-256: 5b9b946f5a3a29bf4a2f1e659b88a259bb7ab40e83d11958f877e8459231c295
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While many of these URLs point to benign-looking book titles, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/7201207204206204/Haunted-Ohio-IV-Restless-Spirits-Haunted-Ohio-Series-by-Chris-Woodyard.pdf
    • http://xiixmcuin.linkpc.net/3208205207206203/Haunted-Ohio-Ghostly-Tales-from-the-Buckeye-State-by-Chris-Woodyard.pdf
    • http://xiixmcuin.linkpc.net/7201207206200208/Haunted-Ohio-III-Still-More-Ghostly-Tales-from-the-Buckeye-State-by-Chris-Woodyard.pdf
    • http://xiixmcuin.linkpc.net/7201207205201204/Ohio-The-Young-Buckeye-State-Blossoms-with-Love-and-Adventure-Ohio-1-4-by-Dianne-Christner.pdf
    • http://xiixmcuin.linkpc.net/7201207207201200/Ohio-Archaeology-An-Illustrated-Chronicle-of-Ohio-s-Ancient-American-Indian-Culture-by-Bradley-T-Lepper.pdf
    • http://xiixmcuin.linkpc.net/1204206205207204/Restless-Spirits-Restless-Spirits-1-by-Jean-Marie-Bauhaus.pdf
    • http://xiixmcuin.linkpc.net/2208207209208208/Hell-and-Ohio-Stories-of-Southern-Appalachia-by-Chris-Holbrook.pdf
    • http://xiixmcuin.linkpc.net/2201207209205207/The-Haunted-Fixer-Upper-Haunted-Renovation-Mystery-2-by-Rose-Pressey.pdf
    • http://xiixmcuin.linkpc.net/7207208207200203/Haunted-Louisiana-The-Haunted-Locations-of-Baton-Rouge-Shreveport-Metairie-and-Lafayette-by-Jeffrey-Fisher.pdf
    • http://xiixmcuin.linkpc.net/1200201203205202201/Gabby-s-Haunted-House-Series-Gabby-s-Haunted-House-1-5-by-Lorrie-Bannett.pdf
    • http://xiixmcuin.linkpc.net/8207206207208205/The-Guide-for-Ohio-School-Officers-Containing-All-the-Law-of-Ohio-Applicable-to-School-Officers-with-Forms-and-Suggestions-for-the-Guidance-of-All-School-Officials-by-William-M-William-Mahlon-185-Rockel.pdf
    • http://xiixmcuin.linkpc.net/2207204202206203/Haunted-Savannah-The-Official-Guidebook-to-Savannah-Haunted-History-Tour-Conducted-by-Cobblestone-Tours-by-James-Caskey.pdf
    • http://xiixmcuin.linkpc.net/3201203201209/The-Hanging-Hill-Haunted-Mystery-2-by-Chris-Grabenstein.pdf
    • http://xiixmcuin.linkpc.net/1209204204206207/House-of-Spirits-amp-Whispers-The-True-Story-of-a-Haunted-House-by-Annie-Wilder.pdf
    • http://xiixmcuin.linkpc.net/1204206207205208/Kindred-Spirits-Restless-Spirits-2-by-Jean-Marie-Bauhaus.pdf
    • http://xiixmcuin.linkpc.net/1204206201209201/Bound-Spirits-Restless-Spirits-3-by-Jean-Marie-Bauhaus.pdf
    • http://xiixmcuin.linkpc.net/1204206201208208/Bound-Spirits-Restless-Spirits-3-by-Jean-Marie-Bauhaus.pdf
    • http://xiixmcuin.linkpc.net/1200200204207201200/Vietnam-Since-The-Fall-Of-Saigon-Ohio-University-Monographs-in-International-Studies-Southeast-Asia-Series-No-56-Revised-Edition-by-William-J-Duiker.pdf
    • http://xiixmcuin.linkpc.net/1208206202201203/Restless-Spirits-Spirits-1-by-Jordan-L-Hawk.pdf
    • http://xiixmcuin.linkpc.net/6207203203206207/Haunted-from-Within-Haunted-from-Within-1-2-by-Ian-C-P-Irvine.pdf