Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d3f0204aea901ad…

MALICIOUS

PDF

21.0 KB Created: 2019-05-02 05:03:27 +01:00 Authoring application: mPDF 5.7
MD5: b64eb71ccc6472cc7c040d3e941b2f97 SHA-1: 4d1aac3c5ec228fa488e42f3cd31337b7da299cc SHA-256: 9d3f0204aea901addd0315b6854c058eccdd926786e1975155662a46425ca81a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4207201206207206/Lunch-Wars-How-to-Start-a-School-Food-Revolution-and-Win-the-Battle-for-Our-Children-s-Health-by-Amy-Kalafa.pdf
    • http://xiixmcuin.linkpc.net/8206205202201206/No-Free-Lunch-Food-amp-Revolution-in-Cuba-Today-by-Medea-Benjamin.pdf
    • http://xiixmcuin.linkpc.net/1200206205209206207/School-Wars-The-Battle-for-Britain-s-Education-by-Melissa-Benn.pdf
    • http://xiixmcuin.linkpc.net/8208205209207204/Positive-Outcomes-in-Health-How-Food-Exercise-and-Your-Immune-System-Lead-to-Good-Health-by-Lee-Oberst.pdf
    • http://xiixmcuin.linkpc.net/1204201209201200/Food-Politics-How-the-Food-Industry-Influences-Nutrition-and-Health-by-Marion-Nestle.pdf
    • http://xiixmcuin.linkpc.net/1201208208208203202/Fresh-Start---SIMPLE-SOLUTIONS-FOR-WEIGHT-LOSS---LUNCH-IDEAS-by-Cory-Rocko.pdf
    • http://xiixmcuin.linkpc.net/1208209203202200/Free-for-All-Fixing-School-Food-in-America-California-Studies-in-Food-and-Culture-28-by-Janet-Poppendieck.pdf
    • http://xiixmcuin.linkpc.net/1203203205209208/Can-You-Get-An-F-In-Lunch-How-I-Survived-Middle-School-1-by-Nancy-E-Krulik.pdf
    • http://xiixmcuin.linkpc.net/4202209202206204/Start-Talking-A-Girl-s-Guide-for-You-and-Your-Mom-about-Health-Sex-or-Whatever-by-Mary-Jo-Rapini.pdf
    • http://xiixmcuin.linkpc.net/6206209208207201/Battles-Involving-Hanover-Battle-of-Waterloo-Battle-of-Dettingen-Battle-of-Fontenoy-Battle-of-Tourcoing-Battle-of-Melle-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/1204207205200209/The-Boys-Start-the-War-Boy-Girl-Battle-1-by-Phyllis-Reynolds-Naylor.pdf
    • http://xiixmcuin.linkpc.net/8201202204203204/Food-and-Drink-Best-Health-Recipe-Book-by-Vesco-Inc.pdf
    • http://xiixmcuin.linkpc.net/8202202203208206/Right-from-the-Start-Behavioral-Intervention-for-Young-Children-with-Autism-by-Sandra-L-Harris.pdf
    • http://xiixmcuin.linkpc.net/2204201203200202/Food-Wars-Vol-1-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/2201200209205200/Food-Wars-Vol-1-by-Yuto-Tsukuda.pdf
    • http://xiixmcuin.linkpc.net/1209200205209200/The-Taste-Of-War-World-War-Two-And-The-Battle-For-Food-by-Lizzie-Collingham.pdf
    • http://xiixmcuin.linkpc.net/6209204208209206/The-Battle-of-Riptide-Sharks-Wars-2-by-E-J-Altbacker.pdf
    • http://xiixmcuin.linkpc.net/3207201206206203/Fields-of-Battle-The-Wars-for-North-America-by-John-Keegan.pdf
    • http://xiixmcuin.linkpc.net/2200208200200204/Blood-Revolution-God-Wars-3-by-Connie-Suttle.pdf
    • http://xiixmcuin.linkpc.net/6207206208203203/On-Red-Soil-WARS-The-Battle-of-Phobos---Earthers-Part-2-of-3-by-Nathan-P-Butler.pdf
    • http://xiixmcuin.linkpc.net/1201208208208