Malicious PDF — malware analysis report

Static analysis result for SHA-256 988edece9a1ef177…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 02:46:31 +01:00 Authoring application: mPDF 5.7
MD5: 3469443ee089295a507c2ea78217dab6 SHA-1: 6623ad0bc60ea1153589320dfad13067ef264e3c SHA-256: 988edece9a1ef177d8949e808b67e92fa7da2873919e84fb65b151b9bca00ff7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this document as malicious. The primary attack pattern observed is the creation of a link farm to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.link
    • http://xiixmcuin.linkpc.net/2202208200200200/Why-Suicide-Answers-to-200-of-the-Most-Frequently-Asked-Questions-about-Suicide-Attempted-Suicide-and-Assisted-Suicide-by-Eric-Marcus.pdf
    • http://xiixmcuin.linkpc.net/7207207204208208/Selected-Papers---Oeuvres-Scientifiques-I-Topology-and-Fixed-Point-Theorems-Topologie-Et-Theoreme-Du-Point-Fixe-Topologie-Et-Theoreme-Du-Point-Fixe-by-Jean-Leray.pdf
    • http://xiixmcuin.linkpc.net/1207202202209206/Reckless-Point-Cross-Point-Village-1-by-Cora-Brent.pdf
    • http://xiixmcuin.linkpc.net/5209202204208202/Le-Point-de-Non-Retour-the-Point-of-No-Return-by-Sharon-Desruisseaux.pdf
    • http://xiixmcuin.linkpc.net/4208200207209208/Breaking-Point-Turning-Point-2-by-N-R-Walker.pdf
    • http://xiixmcuin.linkpc.net/4205204208207209/Breaking-Point-Turning-Point-2-by-N-R-Walker.pdf
    • http://xiixmcuin.linkpc.net/2205206208205203/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://xiixmcuin.linkpc.net/3201207204208206/Point-to-Point-Navigation-by-Gore-Vidal.pdf
    • http://xiixmcuin.linkpc.net/5207206207209/Point-of-No-Return-Turning-Point-1-by-N-R-Walker.pdf
    • http://xiixmcuin.linkpc.net/9201201203200206/The-Point---Unb-ndige-Begierde-Welcome-Point-3-by-Jay-Crownover.pdf
    • http://xiixmcuin.linkpc.net/9205205204202209/The-Point---Entfesselte-Sehnsucht-Welcome-Point-1-by-Jay-Crownover.pdf
    • http://xiixmcuin.linkpc.net/3209200208202208/Hopeful-Leigh-Literal-Leigh-Romance-Diaries-3-by-Melanie-James.pdf
    • http://xiixmcuin.linkpc.net/4207207205208207/The-Best-Medicine-by-Georgie-Edwards.pdf
    • http://xiixmcuin.linkpc.net/3201202208204209/Georgie-by-Robert-Bright.pdf
    • http://xiixmcuin.linkpc.net/3207206200205200/Georgie-by-Robert-Bright.pdf
    • http://xiixmcuin.linkpc.net/4209202201206200/The-Three-Little-Pirates-by-Georgie-Adams.pdf
    • http://xiixmcuin.linkpc.net/3201200208208202/Serious-Leigh-Literal-Leigh-Romance-Diaries-2-by-Melanie-James.pdf
    • http://xiixmcuin.linkpc.net/2209206201208204/Georgie-s-Halloween-by-Robert-Bright.pdf
    • http://xiixmcuin.linkpc.net/3209208204205204/Georgie-and-the-Robbers-by-Robert-Bright.pdf
    • http://xiixmcuin.linkpc.net/1205201200200208/Master-Georgie-by-Beryl-Bainbridge.pdf