Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f37ce7639c1f9f4…

MALICIOUS

PDF

13.5 KB Created: 2019-04-30 04:07:07 +01:00 Authoring application: mPDF 5.7
MD5: bc38c85679ce2a503288b3aa61532b57 SHA-1: 70f72d95acf93fef7d814135dc41008f70082f0f SHA-256: 9f37ce7639c1f9f4d994005cdff60fe59643ffa8d0cda73dfa465926cc8a34d5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, hosted on the dynamic DNS domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a lure to a large collection of potentially malicious content. The ML classifier also flagged this document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4209205203203206/King-s-Knight-s-Pawn-by-John-L-Beatty.pdf
    • http://xiixmcuin.linkpc.net/1205202205208205/A-Donkey-for-the-King-by-John-L-Beatty.pdf
    • http://xiixmcuin.linkpc.net/1205205202201206/Knight-Takes-Pawn-Red-Knight-1-by-Martha-Sweeney.pdf
    • http://xiixmcuin.linkpc.net/3200208201209205/Batman-Begins-The-Movie-and-Other-Tales-of-the-Dark-Knight-by-Scott-Beatty.pdf
    • http://xiixmcuin.linkpc.net/4209205201208203/At-the-Seven-Stars-by-John-L-Beatty.pdf
    • http://xiixmcuin.linkpc.net/4209205203204201/Witch-Dog-by-John-L-Beatty.pdf
    • http://xiixmcuin.linkpc.net/2204207206203209/Master-Rosalind-by-John-L-Beatty.pdf
    • http://xiixmcuin.linkpc.net/4203204205209207/Pawn---Volume-1-Pawn-1-by-Maya-St-James.pdf
    • http://xiixmcuin.linkpc.net/4204203209209208/Pawn---Volume-3-Pawn-3-by-Maya-St-James.pdf
    • http://xiixmcuin.linkpc.net/1201207201204205206/Bishop-s-Pawn-Bishop-s-Pawn-1-by-Suzanne-Halliday.pdf
    • http://xiixmcuin.linkpc.net/4203203204208202/Knight-of-Desire-All-the-King-s-Men-1-by-Margaret-Mallory.pdf
    • http://xiixmcuin.linkpc.net/6209201204208207/King-Lucius-of-Britain-by-David-J-Knight.pdf
    • http://xiixmcuin.linkpc.net/3200201202205/The-King-s-Scrolls-Ilyon-Chronicles-2-by-Jaye-L-Knight.pdf
    • http://xiixmcuin.linkpc.net/1202205209209204/The-King-s-Scrolls-Ilyon-Chronicles-Book-2-by-Jaye-L-Knight.pdf
    • http://xiixmcuin.linkpc.net/8204205201205203/The-Rescue-of-Princess-Chaka-Knight-King-Merlin-and-the-Rapp-Lords-by-Kevin-Curtis-Barr.pdf
    • http://xiixmcuin.linkpc.net/1205206203202202/The-Eyes-of-God-The-Bronze-Knight-1-by-John-Marco.pdf
    • http://xiixmcuin.linkpc.net/1204203204207205/The-Noble-Outlaw-Crowner-John-Mystery-11-by-Bernard-Knight.pdf
    • http://xiixmcuin.linkpc.net/1201209209206206/The-Tinner-s-Corpse-Crowner-John-Mystery-5-by-Bernard-Knight.pdf
    • http://xiixmcuin.linkpc.net/4205201202205205/The-Noble-Outlaw-Crowner-John-Mystery-11-by-Bernard-Knight.pdf
    • http://xiixmcuin.linkpc.net/8205204207209201/Saint-George-Rusty-Knight-and-Monster-Tamer-by-John--Powell.pdf
    • http://xiixmcuin.linkpc.net/6209201204208207/King-Lucius-of-Britain-b