Malicious PDF — malware analysis report

Static analysis result for SHA-256 823c312a8ef8327c…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 18:15:33 +01:00 Authoring application: mPDF 5.7
MD5: a57e81a1b28374479d6f59222181eb7d SHA-1: 0c25694c5e11448ef39fd4d026acd7a4de4a26af SHA-256: 823c312a8ef8327c5a847c3c5237d0d4c0d21efedfc5ad2e6e6ec5a437ac10e3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm. The primary heuristic identified this as a PDF_SEO_LINK_FARM, indicating a likely attempt to direct users to external content, potentially malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc
    • http://xiixmcuin.linkpc.net/2202209207207204/Tomes-of-the-Dead-Hungry-Hearts-by-Gary-McMahon.pdf
    • http://xiixmcuin.linkpc.net/5204203204209208/All-Things-Pretty-Part-Two-Pretty-3-5-by-Michelle-Leighton.pdf
    • http://xiixmcuin.linkpc.net/9205207208204/The-End-by-Gary-McMahon.pdf
    • http://xiixmcuin.linkpc.net/4200201200208207/Children-Shouldn-t-Play-with-Dead-Things-Dead-Things-1-by-Martina-McAtee.pdf
    • http://xiixmcuin.linkpc.net/9205209208205/How-To-Make-Monsters-by-Gary-McMahon.pdf
    • http://xiixmcuin.linkpc.net/1207205201203202/Dark-Dreams-and-Dead-Things-Dead-Things-2-by-Martina-McAtee.pdf
    • http://xiixmcuin.linkpc.net/5209203209203/Dead-Girls-Dead-Boys-Dead-Things-by-Richard-Calder.pdf
    • http://xiixmcuin.linkpc.net/2208207201206207/Pretty-Little-Things-by-Jilliane-Hoffman.pdf
    • http://xiixmcuin.linkpc.net/2208206201206203/Little-Pretty-Things-by-Lori-Rader-Day.pdf
    • http://xiixmcuin.linkpc.net/9208203201/Dirty-Pretty-Things-by-Michael-Faudet.pdf
    • http://xiixmcuin.linkpc.net/2203201205202207/Shiny-Broken-Pieces-Tiny-Pretty-Things-2-by-Sona-Charaipotra.pdf
    • http://xiixmcuin.linkpc.net/5203206208204209/Pretty-Dead-Elise-Sandburg-3-by-Anne-Frasier.pdf
    • http://xiixmcuin.linkpc.net/8202208202205207/Things-Left-Behind-by-Gary-A-Braunbeck.pdf
    • http://xiixmcuin.linkpc.net/8202208202206202/Our-Things-The-Oilman-by-Gary-A-Braunbeck.pdf
    • http://xiixmcuin.linkpc.net/5205209204200202/True-Blood-Collection-Dead-Reckoning-Dead-in-the-Family-a-Touch-of-Dead-Dead-and-Gone-Dead-to-the-World-Dead-as-a-Doornail-All-Together-Dead-and-More-by-Charlaine-Harris.pdf
    • http://xiixmcuin.linkpc.net/2207201205206205/When-Sorry-Isn-t-Enough-Making-Things-Right-with-Those-You-Love-by-Gary-Chapman.pdf
    • http://xiixmcuin.linkpc.net/6206208202207201/Pretty-Hip-amp-Dead-Agnes-Barton-Kimberly-Steele-Mystery-1-by-Madison-Johns.pdf
    • http://xiixmcuin.linkpc.net/3203209205203209/Things-Good-Girls-Don-t-Do-Rock-Canyon-Idaho-1-by-Codi-Gary.pdf
    • http://xiixmcuin.linkpc.net/5201202207209201/The-Michigan-Book-of-Bests-An-Eclectic-Barrage-of-Great-Places-to-Go-and-Things-to-Know-by-Gary-W-Barfknecht.pdf
    • http://xiixmcuin.linkpc.net/5200202205204200/Holy-Ghosts-Or-How-a-Not-So-Good-Catholic-Boy-Became-a-Believer-in-Things-That-Go-Bump-in-the-Night-by-Gary-Jansen.pdf