Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e5a7f6b2c4d5949…

MALICIOUS

PDF

16.3 KB Created: 2019-05-07 04:11:30 +01:00 Authoring application: mPDF 5.7
MD5: e1c795be649132ebd881aa683c9a92df SHA-1: 6c86813cc61e37e88ba71c1e050db06b23167942 SHA-256: 9e5a7f6b2c4d59490b26d1a50b963e7c930158e2f696cbef4c9d0babc492e267
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these specific URLs were labeled as confirmed benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to serve as a lure for further malicious activity. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4209209206202201/Flee-from-Evil-Water-s-Edge-1-by-Connie-Almony.pdf
    • http://xiixmcuin.linkpc.net/2200203208209205/At-the-Edge-of-a-Dark-Forest-by-Connie-Almony.pdf
    • http://xiixmcuin.linkpc.net/3200206205200203/At-the-Edge-of-a-Dark-Forest-by-Connie-Almony.pdf
    • http://xiixmcuin.linkpc.net/4202202202204206/One-Among-Men-The-Maryland-State-University-1-by-Connie-Almony.pdf
    • http://xiixmcuin.linkpc.net/5203205205202206/Water-s-Edge-by-Genevieve-Fortin.pdf
    • http://xiixmcuin.linkpc.net/9206202/Wet-The-Water-s-Edge-1-by-Stacy-Kestwick.pdf
    • http://xiixmcuin.linkpc.net/9208208208206207/Evil-Water-Daniel-Trokic-5-by-Inger-Wolf.pdf
    • http://xiixmcuin.linkpc.net/1200209201200206/Water-s-Edge-Troubled-Times-1-by-Rachel-Meehan.pdf
    • http://xiixmcuin.linkpc.net/4200204200203208/At-Water-s-Edge-An-Epic-Fantasy-The-Last-Elentrice-Book-1-by-S-McPherson.pdf
    • http://xiixmcuin.linkpc.net/7208208203204200/Standing-at-the-Water-s-Edge-Bob-Straub-s-Battle-for-the-Soul-of-Oregon-by-Charles-K-Johnson.pdf
    • http://xiixmcuin.linkpc.net/1200208201204200203/Saline-Water-Processing-Desalination-And-Treatment-Of-Seawater-Brackish-Water-And-Industrial-Waste-Water-by-Hans-Gunter-Heitmann.pdf
    • http://xiixmcuin.linkpc.net/3209208204207207/Land-Where-I-Flee-by-Prajwal-Parajuly.pdf
    • http://xiixmcuin.linkpc.net/5203209201206207/The-Wicked-Flee-Marty-Singer-5-by-Matthew-Iden.pdf
    • http://xiixmcuin.linkpc.net/2201201206203202/The-Edge-of-Never-The-Edge-of-Always-Two-Book-Collection-The-Edge-of-Never-1-2-by-J-A-Redmerski.pdf
    • http://xiixmcuin.linkpc.net/6209200205201206/Flee-The-Night-Cheating-Infidelity-and-Adultery-Series-by-Jezabel-Presley.pdf
    • http://xiixmcuin.linkpc.net/4207202209205/Sense-of-Evil-Bishop-Special-Crimes-Unit-6-Evil-3-by-Kay-Hooper.pdf
    • http://xiixmcuin.linkpc.net/4203204204200200/Speak-No-Evil-No-Evil-Trilogy-1-by-Allison-Brennan.pdf
    • http://xiixmcuin.linkpc.net/2209204207200203/Hearing-Evil-Cycle-of-Evil-2-by-Jason-Parent.pdf
    • http://xiixmcuin.linkpc.net/1206203206201200/Just-Evil-Evil-Secrets-Trilogy-1-by-Vickie-McKeehan.pdf
    • http://xiixmcuin.linkpc.net/3204205209205202/Evil-Unto-Evil-Rune-Breaker-4-by-Landon-Porter.pdf
    • http://xiixmcuin.linkpc.net/1200208201204200203/Saline-Water-Processing-Desalin