Malicious PDF — malware analysis report

Static analysis result for SHA-256 954357a07e5f0f99…

MALICIOUS

PDF

16.2 KB Created: 2019-04-30 18:00:50 +01:00 Authoring application: mPDF 5.7
MD5: c3fb42dc0e10d6a176998e977919509e SHA-1: a82a9155d735d27f7c7c2a80a2ffd4637d7fb3aa SHA-256: 954357a07e5f0f992b1546f6da9d6118cdbd61d4e064beda4beac51015519484
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF was flagged by a machine learning classifier and contains a large number of external links, indicating a potential SEO manipulation or content hosting scheme. The embedded URLs, while marked as benign in isolation, are part of a link farm structure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.n
    • http://xiixmcuin.linkpc.net/1208203203201206/Rusty-s-Kitchen-Holiday-Dog-Treats-by-Elizabeth-Clements.pdf
    • http://xiixmcuin.linkpc.net/3202200204205205/The-Jacket-by-Andrew-Clements.pdf
    • http://xiixmcuin.linkpc.net/1203206206203/Frindle-by-Andrew-Clements.pdf
    • http://xiixmcuin.linkpc.net/1200206200200206/The-Landry-News-by-Andrew-Clements.pdf
    • http://xiixmcuin.linkpc.net/6208208207203208/In-Harm-s-Way-Benjamin-Pratt-amp-the-Keepers-of-the-School-4-by-Andrew-Clements.pdf
    • http://xiixmcuin.linkpc.net/3201206204204205/The-Whites-of-Their-Eyes-Benjamin-Pratt-amp-the-Keepers-of-the-School-3-by-Andrew-Clements.pdf
    • http://xiixmcuin.linkpc.net/2207205207206/Things-Not-Seen-Things-1-by-Andrew-Clements.pdf
    • http://xiixmcuin.linkpc.net/7206201209207207/Fiddle-Tab---Holiday-Collection-30-Holiday-Classics-for-Easy-Violin-by-Brent-Robitaille.pdf
    • http://xiixmcuin.linkpc.net/3207204205207208/Wild-Holiday-Nights-Holiday-Rush-Playing-Games-All-Night-Long-by-Samantha-Hunter.pdf
    • http://xiixmcuin.linkpc.net/2202205202200202/Holiday-Kisses-A-Holiday-Romance-Collection-by-Jaci-Burton.pdf
    • http://xiixmcuin.linkpc.net/8200200205203204/A-Holiday-Christmas-Holiday-Vermont-2-5-by-Heather-Lire.pdf
    • http://xiixmcuin.linkpc.net/1200201207202207207/Haley-s-Hangdog-Holiday-Holiday-Inc-2-by-Tamie-Dearen.pdf
    • http://xiixmcuin.linkpc.net/2207203206208200/In-Concert-by-Karin-Bishop.pdf
    • http://xiixmcuin.linkpc.net/1200204203203202204/Moses-Goes-to-a-Concert-by-Isaac-Millman.pdf
    • http://xiixmcuin.linkpc.net/3202208208204203/Snowman-Paul-at-the-CONCERT-HALL-by-Yossi-Lapid.pdf
    • http://xiixmcuin.linkpc.net/3204201205207204/The-Concert-Killer-Rock-amp-Roll-Mystery-Series-by-R-J-McDonnell.pdf
    • http://xiixmcuin.linkpc.net/9203201209203206/In-the-Pipeline-Memoirs-of-an-International-Concert-Organist-by-Carlo-Curley.pdf
    • http://xiixmcuin.linkpc.net/8203204202208201/Morceau-de-Concert-Opus-94-For-Horn-and-Piano-0-by-Camille-Saint-Sa-ns.pdf
    • http://xiixmcuin.linkpc.net/8203204201206205/Morceau-de-Concert-Op-94-F-Horn-Feature-Score-amp-Parts-by-Camille-Saint-Sa-ns.pdf
    • http://xiixmcuin.linkpc.net/8203204202207207/Morceau-Symphonique-Solo-Trombone-and-Concert-Band-Conductor-Score-by-Alexandre-Guilmant.pdf