Malicious PDF — malware analysis report

Static analysis result for SHA-256 83468beac8593bdd…

MALICIOUS

PDF

17.9 KB Created: 2019-04-30 18:34:27 +01:00 Authoring application: mPDF 5.7
MD5: 2001e201f8c07d9c854e4d60f662754c SHA-1: cd4ad28b18487b5cc06510260633fc92c4bf59c0 SHA-256: 83468beac8593bdd7e697b5a32d825253057fc4415def02b6f00bec60065455f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, such as http://xiixmcuin.linkpc.net/5205200204204207/The-Wind-Spirit-An-Autobiography-by-Michel-Tournier.pdf, are likely used to redirect users to potentially harmful content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5205200204204207/The-Wind-Spirit-An-Autobiography-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/4205202202209201/The-Erl-King-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200203207206/The-Four-Wise-Men-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/1206205202207201/Gemini-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/6203205203200207/The-Education-Of-Robinson-Crusoe-A-Study-Of-Vendredi-Ou-La-Vie-Sauvage-By-Michel-Tournier-by-F-J-Fornasiero.pdf
    • http://xiixmcuin.linkpc.net/7207206202205205/Lettres-parl-es-son-ami-allemand-Hellmut-Waller-1967-1998-Hors-s-rie-Litt-rature-by-Michel-Tournier.pdf
    • http://xiixmcuin.linkpc.net/1208209201207/The-Wind-Is-Spirit-The-Life-Love-and-Legacy-of-Audre-Lorde-by-Gloria-I-Joseph.pdf
    • http://xiixmcuin.linkpc.net/1201207202204206203/Spiritual-Interview-with-the-Guardian-Spirit-of-Malala-Yousafzai-A-Wind-of-Hope-for-the-Islamic-World-by-Ryuho-Okawa.pdf
    • http://xiixmcuin.linkpc.net/7203201202209/Fresh-Wind-Fresh-Fire-What-Happens-When-God-s-Spirit-Invades-the-Heart-of-His-People-by-Jim-Cymbala.pdf
    • http://xiixmcuin.linkpc.net/5205200203208203/To-Understand-Each-Other-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200204205206/Learn-to-Grow-Old-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/1204202207203203/The-Statue-Within-An-Autobiography-An-Autobiography-by-Fran-ois-Jacob.pdf
    • http://xiixmcuin.linkpc.net/5205200204205202/The-Whole-Person-in-a-Broken-World-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/5205200204205200/A-Place-for-You-Psychology-and-Religion-by-Paul-Tournier.pdf
    • http://xiixmcuin.linkpc.net/3202208200201206/Chasers-of-the-Wind-The-Cycle-of-Wind-and-Sparks-1-by-Alexey-Pehov.pdf
    • http://xiixmcuin.linkpc.net/3202206208203200/Sweet-Wind-Wild-Wind-by-Elizabeth-Lowell.pdf
    • http://xiixmcuin.linkpc.net/4204201209200/The-Wind-Singer-Wind-on-Fire-1-by-William-Nicholson.pdf
    • http://xiixmcuin.linkpc.net/2207204206204208/Reap-The-Wind-Wind-Dancer-3-by-Iris-Johansen.pdf
    • http://xiixmcuin.linkpc.net/4201207206205204/Spirit-Warrior-Spirit-Pass-2-by-S-E-Smith.pdf
    • http://xiixmcuin.linkpc.net/5209203208201202/Oeuvres-de-Michel-Z-vaco-Borgia-les-Pardaillan-le-Pont-des-Soupirs-by-Michel-Z-vaco.pdf
    • http://xiixmcuin.linkpc.net/120120720220420620