Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c6beeb326becccc…

MALICIOUS

PDF

14.6 KB Created: 2019-05-05 17:30:21 +01:00 Authoring application: mPDF 5.7
MD5: 13b8221a81fb4532a81b4b071bb754c6 SHA-1: 60486ddc27221796cd6dc0629a17076e525ae807 SHA-256: 9c6beeb326becccc15e437e176d35c9a2416479bc7ab5529d5254534fe3c46e5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, forming a link farm, with the dominant host being xiixmcuin.linkpc.net. While the specific URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9200

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2202204209205200/Outline-by-Rachel-Cusk.pdf
    • http://xiixmcuin.linkpc.net/3206201205208/In-the-Fold-by-Rachel-Cusk.pdf
    • http://xiixmcuin.linkpc.net/1201203201201205/The-Country-Life-by-Rachel-Cusk.pdf
    • http://xiixmcuin.linkpc.net/1208202203207205/Rachel-and-the-Many-Splendored-Dreamland-Rachel-Griffin-3-by-L-Jagi-Lamplighter.pdf
    • http://xiixmcuin.linkpc.net/1208202203207204/The-Raven-the-Elf-and-Rachel-Rachel-Griffin-2-by-L-Jagi-Lamplighter.pdf
    • http://xiixmcuin.linkpc.net/1203207203201202/Rachel-Plummer-s-Narrative-Of-21-Months-Servitude-As-A-Prisoner-Among-The-Comanche-Indians-by-Rachel-Plummer.pdf
    • http://xiixmcuin.linkpc.net/4204204200205208/Rachel-Calof-s-Story-Jewish-Homesteader-on-the-Northern-Plains-by-Rachel-Calof.pdf
    • http://xiixmcuin.linkpc.net/1201202202207202/The-Unexpected-Enlightenment-of-Rachel-Griffin-Rachel-Griffin-1-by-L-Jagi-Lamplighter.pdf
    • http://xiixmcuin.linkpc.net/5206204201200201/Murder-in-Emerald-Hills-A-Rachel-Christie-Mystery-2-Rachel-Christie-Mystery-Series-by-Sabena-Stone.pdf
    • http://xiixmcuin.linkpc.net/1208206201200207/How-To-Be-Someone-Else-by-Rachel-Del.pdf
    • http://xiixmcuin.linkpc.net/2200202203205204/With-Malice-by-Rachel-Lee.pdf
    • http://xiixmcuin.linkpc.net/4205209202202205/I-Do-by-Rachel-Gibson.pdf
    • http://xiixmcuin.linkpc.net/6207204201207/Afterwards-by-Rachel-Seiffert.pdf
    • http://xiixmcuin.linkpc.net/3202207201208201/Me-and-Mr-J-by-Rachel-McIntyre.pdf
    • http://xiixmcuin.linkpc.net/4201204205206200/Everything-Under-the-Sun-by-Rachel-West.pdf
    • http://xiixmcuin.linkpc.net/5200205205205203/Co-Ed-by-Rachel-Van-Dyken.pdf
    • http://xiixmcuin.linkpc.net/4205209202209205/Run-To-You-Military-Men-2-by-Rachel-Gibson.pdf
    • http://xiixmcuin.linkpc.net/3204202206208202/Under-the-Sea-Wind-by-Rachel-Carson.pdf
    • http://xiixmcuin.linkpc.net/3201208206203200/Perfect-by-Rachel-Joyce.pdf
    • http://xiixmcuin.linkpc.net/1209201205204205/Every-Girl-Does-It-by-Rachel-Van-Dyken.pdf
    • http://xiixmcuin.linkpc.net/1201202202207202/The-Unexpected-Enlightenment-of-Rachel-Griffin-Rac