Malicious PDF — malware analysis report

Static analysis result for SHA-256 8876b532ff2db367…

MALICIOUS

PDF

13.4 KB Created: 2019-04-30 03:25:51 +01:00 Authoring application: mPDF 5.7
MD5: 2568743ff0df6c95252a7f2c0b1dc1a4 SHA-1: 8c219a691a06d1cf48efb676a77a5919dc1a0449 SHA-256: 8876b532ff2db367c9157e60e9fc2d1030b2a5cbad998e5c1c3da46ff023a27c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin
    • http://xiixmcuin.linkpc.net/2202206209204200/Forever-Love-Forever-Love-1-2-by-Megan-Smith.pdf
    • http://xiixmcuin.linkpc.net/2200207209208/Kiss-Me-Forever-Love-Me-Forever-Forever-Vampires-1-2-by-Rosemary-Laurey.pdf
    • http://xiixmcuin.linkpc.net/3209200206200208/Forever-Together-The-Forever-Love-Series-2-by-Jade-Whitfield.pdf
    • http://xiixmcuin.linkpc.net/1203203201202205/Forever-Love-Now-amp-Forever-3-by-Melissa-Johns.pdf
    • http://xiixmcuin.linkpc.net/3205201203207202/Remember-Love-The-Forever-Love-Series-1-by-Riley-Rhea.pdf
    • http://xiixmcuin.linkpc.net/3205200200206201/Made-to-Love-You-Love-5-by-Megan-Smith.pdf
    • http://xiixmcuin.linkpc.net/7208202205205208/The-Forever-War-Series-The-Forever-War-A-Separate-War-and-Forever-Free-by-Joe-Haldeman.pdf
    • http://xiixmcuin.linkpc.net/1207204201200202/Need-to-Love-You-Love-6-by-Megan-Smith.pdf
    • http://xiixmcuin.linkpc.net/1204207207203204/Let-Me-Love-You-Love-4-by-Megan-Smith.pdf
    • http://xiixmcuin.linkpc.net/1201209204205206/Once-And-Forever-Love-by-D-J-Phillabaum.pdf
    • http://xiixmcuin.linkpc.net/1203201205208207/Before-Lucky-Forever-Love-2-5-by-J-S-Cooper.pdf
    • http://xiixmcuin.linkpc.net/3206205209206209/My-Forever-Love-by-Marsha-Canham.pdf
    • http://xiixmcuin.linkpc.net/1209207203201205/Love-You-Forever-Only-In-That-Way-by-Saurabh-Dudeja.pdf
    • http://xiixmcuin.linkpc.net/3202203208204/Love-You-Forever-by-Robert-Munsch.pdf
    • http://xiixmcuin.linkpc.net/5200204209201201/Love-After-Marriage-Forever-After-2-by-Mia-Kayla.pdf
    • http://xiixmcuin.linkpc.net/7203200203202/Forever-My-Love-by-Rebecca-Brandewyne.pdf
    • http://xiixmcuin.linkpc.net/1204205204200201/First-Love-Now-amp-Forever-1-by-Melissa-Johns.pdf
    • http://xiixmcuin.linkpc.net/8208208206207/Finally-Forever-First-Comes-Love-3-by-Katie-Kacvinsky.pdf
    • http://xiixmcuin.linkpc.net/3204201203202204/Love-or-Lust-Now-amp-Forever-1-by-Jaye-Em-Edgecliff.pdf
    • http://xiixmcuin.linkpc.net/3204202200204201/Love-Me-Forever-Scottish-Duo-2-by-Donna-Fletcher.pdf