Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d90aba499b149dc…

MALICIOUS

PDF

16.7 KB Created: 2019-05-01 17:15:11 +01:00 Authoring application: mPDF 5.7
MD5: d520db819979a0ec70efa71df51e90f5 SHA-1: 412f38484c7decd7a4b83c0131e8d41e69e02f4f SHA-256: 6d90aba499b149dc00420be061fcc7677a9a0ca12601b3db52461604665edf7e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. While the specific content of the linked PDFs is benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' indicate a suspicious pattern. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3208209204206208/Eden-s-Serum-Eden-Series-1-by-Angelique-S-Anderson.pdf
    • http://xiixmcuin.linkpc.net/6202209204206201/Eden-s-Serum-Eden-Series-1-by-Angelique-S-Anderson.pdf
    • http://xiixmcuin.linkpc.net/4209205202200207/Finding-Eden-The-Eden-Hall-Series-by-Sheri-Richey.pdf
    • http://xiixmcuin.linkpc.net/3201206205203201/Waiting-for-Eden-Eden-Series-1-by-Jessica-Leigh.pdf
    • http://xiixmcuin.linkpc.net/4201204205202201/Angelique-Angelique-and-the-King-Angelique-in-Barbary-Angelique-in-Revolt-Angelique-in-Love-The-Countess-Angelique-Temptation-of-Angelique-Angelique-and-the-Demon-Angelique-and-the-Ghosts-9-Volume-Set-by-Anne-Golon.pdf
    • http://xiixmcuin.linkpc.net/1207201209204201/Pleasure-Point-San-Francisco-Dom-3-Invitation-to-Eden-16-by-Eden-Bradley.pdf
    • http://xiixmcuin.linkpc.net/1201204208206200/Fallen-Eden-Eden-Trilogy-2-by-Nicole-Williams.pdf
    • http://xiixmcuin.linkpc.net/3203207208205200/Kane-Volume-1-Greetings-From-New-Eden-Greetings-from-New-Eden-v-1-by-Paul-Grist.pdf
    • http://xiixmcuin.linkpc.net/1202206206206209/Dawn-of-Eden-Blood-of-Eden-0-5-by-Julie-Kagawa.pdf
    • http://xiixmcuin.linkpc.net/1202206205201202/Rebels-of-Eden-Children-of-Eden-3-by-Joey-Graceffa.pdf
    • http://xiixmcuin.linkpc.net/2200205208204208/Finding-Eden-Eden-2-by-Kele-Moon.pdf
    • http://xiixmcuin.linkpc.net/3204201204205206/The-Women-of-Eden-Eden-4-by-Marilyn-Harris.pdf
    • http://xiixmcuin.linkpc.net/2203202208202209/Eden-III-The-Eden-Trilogy-3-by-Georgia-Le-Carre.pdf
    • http://xiixmcuin.linkpc.net/2204201207203200/Eden-West-Eden-2-by-Janelle-Stalder.pdf
    • http://xiixmcuin.linkpc.net/4206207202209203/West-of-Eden-Eden-No-1-by-Harry-Harrison.pdf
    • http://xiixmcuin.linkpc.net/3200209209202203/Unexpected-Eden-Eden-1-by-Rhenna-Morgan.pdf
    • http://xiixmcuin.linkpc.net/4209206207201204/Eden-s-Wish-Eden-of-the-Lamp-1-by-M-Tara-Crowl.pdf
    • http://xiixmcuin.linkpc.net/1201200203201207/The-Garden-of-Eden-The-Eden-Chronicles-1-by-L-L-Hunter.pdf
    • http://xiixmcuin.linkpc.net/2206204209201200/Eden-Eden-1-by-Louise-Wise.pdf
    • http://xiixmcuin.linkpc.net/1201208204204202201/--husk-of-eden-2-Husk-Eden-2-by-Yoshinori-Kisaragi.pdf