Malicious PDF — malware analysis report

Static analysis result for SHA-256 71d09f94e380c0bb…

MALICIOUS

PDF

16.2 KB Created: 2019-05-03 19:40:17 +01:00 Authoring application: mPDF 5.7
MD5: 1a61cfaff60249f2db8fb2c5bbfc7a99 SHA-1: df6d80b0b63a5f595f10469dd84d3f9d835c7a3d SHA-256: 71d09f94e380c0bb4a0e62cba81e58a0bb59bbe305f26b40b0716b137ac08897
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the suspicious domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8203207208206200/Barbri-The-Conviser-Mini-Review-by-BAR-BRI.pdf
    • http://xiixmcuin.linkpc.net/1200207200204203208/Healthy-Dairy-Free-Eating-Mini-C-with-Tanya-Haffner-by-Mini-C.pdf
    • http://xiixmcuin.linkpc.net/4208200209209208/The-Paris-Review-Interviews-II-Wisdom-from-the-World-s-Literary-Masters-by-The-Paris-Review.pdf
    • http://xiixmcuin.linkpc.net/1201201209204207201/Development-and-Evaluation-of-Value-Based-Review-Vbr-Methods---1-Developing-Value-Based-Checklists-and-Value-Based-Review-Process-by-Keun-Lee.pdf
    • http://xiixmcuin.linkpc.net/1201207208209209202/Themis-Texas-Bar-Review-Set-2014-2015-by-Themis-Bar-Review.pdf
    • http://xiixmcuin.linkpc.net/1201200205206202207/Fjords-Review-Volume-2-Issue-2-by-Fjords-Review.pdf
    • http://xiixmcuin.linkpc.net/1201207208209208207/Themis-Bar-Review-Florida-2015-by-Themis-Bar-Review.pdf
    • http://xiixmcuin.linkpc.net/7207206207207208/The-Literary-Review-Loss-Control-by-The-Literary-Review.pdf
    • http://xiixmcuin.linkpc.net/3201203206201209/The-Paris-Review-Interviews-IV-by-The-Paris-Review.pdf
    • http://xiixmcuin.linkpc.net/1205206200209201/James-and-the-Mini-by-Minerva-Taylor.pdf
    • http://xiixmcuin.linkpc.net/8209202204203207/Escape-of-the-Mini-Mummy-by-Lin-Oliver.pdf
    • http://xiixmcuin.linkpc.net/9204200203206204/Mini-no-es-una-miedica-by-Christine-N-stlinger.pdf
    • http://xiixmcuin.linkpc.net/9204200202205203/Mini-Muss-In-Die-Schule-by-Christine-N-stlinger.pdf
    • http://xiixmcuin.linkpc.net/9205203200200207/The-Trouble-With-Gran-Mini-Book-by-Babette-Cole.pdf
    • http://xiixmcuin.linkpc.net/4206207204201207/Under-Ground-The-Diamond-Mini-Series-Book-1-by-J-M-Zuniga.pdf
    • http://xiixmcuin.linkpc.net/7206206207201/Mini-Skirts-and-Laughter-Lines-by-Carol-E-Wyer.pdf
    • http://xiixmcuin.linkpc.net/4208209208209200/The-Billionaire-s-Baby-Harlequin-Mini-19-by-Leanne-Banks.pdf
    • http://xiixmcuin.linkpc.net/1201202201206207209/Munch-Mini-Board-Book-by-Matthew-Van-Fleet.pdf
    • http://xiixmcuin.linkpc.net/6204202206208204/Pinkalicious-and-Aqua-the-Mini-Mermaid-by-Victoria-Kann.pdf
    • http://xiixmcuin.linkpc.net/1201200208206201202/Film-Noirs-and-Mini-Bars-by-John-Kemp.pdf