Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c6423b821b9a0ed…

MALICIOUS

PDF

15.9 KB Created: 2019-04-30 04:48:42 +01:00 Authoring application: mPDF 5.7
MD5: f4dc6f9dcc7b3f9a2ac50076be4bc130 SHA-1: cbc73162d65bb0ebfb65738e3a384748c5524813 SHA-256: 8c6423b821b9a0ed5411992fbbaeee72dcbd5cfc77da16961866fabbc6214879
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to direct users to harmful content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin
    • http://xiixmcuin.linkpc.net/5205202208209207/Concrete-Designers-Manual-Tables-and-Diagrams-for-the-Design-of-Reinforced-Concrete-Structures-by-George-A-Hool.pdf
    • http://xiixmcuin.linkpc.net/6203206209200206/Condensed-Silica-Fume-In-Concrete-by-Fip-Commission-On-Concrete.pdf
    • http://xiixmcuin.linkpc.net/5207207209202207/Landscape-in-the-Longue-Dur-e-A-History-and-Theory-of-Pebbles-in-a-Pebbled-Heathland-Landscape-by-Christopher-Tilley.pdf
    • http://xiixmcuin.linkpc.net/2202201204209209/The-Gift-by-Werner-A-Lind.pdf
    • http://xiixmcuin.linkpc.net/1208202201207207/Her-Cyborg-Bound-by-Her-1-by-Nellie-C-Lind.pdf
    • http://xiixmcuin.linkpc.net/9208207200206201/Jenny-Lind-by-Edward-Wagenknecht.pdf
    • http://xiixmcuin.linkpc.net/9208207201205205/The-American-Way-of-Strategy-by-Michael-Lind.pdf
    • http://xiixmcuin.linkpc.net/9208207200206209/Knitting-In-The-Nordic-Tradition-by-Vibeke-Lind.pdf
    • http://xiixmcuin.linkpc.net/9208207200206205/Jenny-Lind-s-America-by-Frances-Cavanah.pdf
    • http://xiixmcuin.linkpc.net/1207207202204207/Harbinger-Ophelia-Lind-1-by-Peta-Crake.pdf
    • http://xiixmcuin.linkpc.net/1201206200204203203/Die-wei-e-Nachtigall-Das-Geheimnis-der-Assassinin-by-T-E-Lind.pdf
    • http://xiixmcuin.linkpc.net/9208206209209202/Sacrifice-Ophelia-Lind-2-by-Peta-Crake.pdf
    • http://xiixmcuin.linkpc.net/1208209207208204/Up-from-Conservatism-Why-the-Right-is-Wrong-for-America-by-Michael-Lind.pdf
    • http://xiixmcuin.linkpc.net/4203204209208206/Feint-of-Art-An-Art-Lover-s-Mystery-1-by-Hailey-Lind.pdf
    • http://xiixmcuin.linkpc.net/9208206209204200/Jenny-Lind-and-her-Listening-Cat-by-Frances-Cavanah.pdf
    • http://xiixmcuin.linkpc.net/1200204203209200202/Eine-Handvoll-Heldinnen-Roman-by-Hera-Lind.pdf
    • http://xiixmcuin.linkpc.net/9208206209203208/Arsenic-and-Old-Paint-An-Art-Lover-s-Mystery-4-by-Hailey-Lind.pdf
    • http://xiixmcuin.linkpc.net/8206209208202205/Joyce-Wieland-Artist-on-Fire-by-Jane-Lind.pdf
    • http://xiixmcuin.linkpc.net/3207206200207201/Shooting-Gallery-An-Art-Lover-s-Mystery-2-by-Hailey-Lind.pdf
    • http://xiixmcuin.linkpc.net/9205201208208208/Concrete-and-Sustainability-by-Per-Jahren.pdf