Malicious PDF — malware analysis report

Static analysis result for SHA-256 657f5e47bb536284…

MALICIOUS

PDF

15.8 KB Created: 2019-05-03 12:22:23 +01:00 Authoring application: mPDF 5.7
MD5: fe51e04876051496ce7b422746c4fe05 SHA-1: 5bd3c3aa2b001bcc59501f4affd4495fea26e3da SHA-256: 657f5e47bb53628407af3e7c39b70ca355533053c2a406ff8349fc0986281dcc
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farm or a phishing attempt. The ML classifier also flagged the document as malicious. While the specific URLs are marked as benign, the sheer volume and the heuristic firing indicate a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201204201209203208/Gone-to-Her-Grave-Rogue-River-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/1201204201209204200/Walking-on-Her-Grave-Rogue-River-4-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/4205200205/Burned-by-Her-Devotion-Rogue-Vows-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/7200208209202200/On-Her-Father-s-Grave-Rogue-River-1-by-Kendra-Elliot.pdf
    • http://xiixmcuin.linkpc.net/7200208209202202/Her-Grave-Secrets-Rogue-River-3-by-Kendra-Elliot.pdf
    • http://xiixmcuin.linkpc.net/2204209200204209/She-Can-Hide-She-Can-4-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/4205201203204200/She-Can-Kill-She-Can-5-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2205208202205203/He-Can-Fall-She-Can-4-5-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2202204205/She-Can-Kill-She-Can-5-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2200205205205206/Midnight-Betrayal-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/7202206202205208/Her-Last-Goodbye-Morgan-Dane-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/3201206207202202/Hour-of-Need-Scarlet-Falls-1-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/9200208202/A-Bone-to-Pick-Widow-s-Island-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/1200207206202203207/Arge-County-Geography-Introduction-Raul-Doamnei-Raul-Targului-Bratia-River-Bughea-River-Arge-El-River-Valea-Brusturetului-River-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/9202202207204/Grave-Measures-The-Grave-Report-2-by-R-R-Virdi.pdf
    • http://xiixmcuin.linkpc.net/1207200209209202/The-Rogue-Best-friends-BDSM-themed-romance-novella-The-Rogue-Club-Book-1-by-Nora-Skye.pdf
    • http://xiixmcuin.linkpc.net/2209209205209204/The-Rogue-s-Omega-The-Rogue-Pack-1-by-Samantha-Cayto.pdf
    • http://xiixmcuin.linkpc.net/3201209203201207/Rogue-s-Curse-Rogue-Prophet-1-by-Jason-Beymer.pdf
    • http://xiixmcuin.linkpc.net/9206206200202203/The-Last-Rogue-Rogue-Trilogy-3-by-Connie-Mason.pdf
    • http://xiixmcuin.linkpc.net/4204202205208202/Rogue-of-the-Borders-Rogue-3-by-Cynthia-Breeding.pdf