Malicious PDF — malware analysis report

Static analysis result for SHA-256 a0c3d41c507789ab…

MALICIOUS

PDF

29.2 KB Created: 2019-05-02 08:24:49 +01:00 Authoring application: mPDF 5.7
MD5: 0b5d550d8e1dee99e4e0020f2ff61772 SHA-1: c83cb6bb179d7bf96212850cd474a39a627cc40f SHA-256: a0c3d41c507789ab3164ce8fe06e58dbc2a3af57b75ffd3309b7dac7dcee431d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking recipe books, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.link
    • http://xiixmcuin.linkpc.net/1201202202205208203/Sayuri-s-Food-for-Yogis-and-Everyone-Easy-delicious-healthy-vegan-recipes-with-gluten-free-alternatives-which-Sayuri-prepares-at-yoga-retreats-around-and-detox-Sayuri-s-Vegan-cookbook-Book-1-by-Sayuri-Tanaka.pdf
    • http://xiixmcuin.linkpc.net/1201202202207201208/Sayuri-s-Raw-Food-Cafe-Easy-Delicious-Healthy-Raw-vegan-vegetarian-gluten-free-diet-and-dessert-to-nourish-your-body-and-heart-as-well-as-healing-and-Sayuri-s-Raw-Food-cookbook-Book-1-by-Sayuri-Tanaka.pdf
    • http://xiixmcuin.linkpc.net/1208203202207202/Vegan-Cookbook-200-Healthy-amp-Delicious-Recipes-For-The-Beginner-Vegan-by-Jared-Bangerter.pdf
    • http://xiixmcuin.linkpc.net/7205209206205200/The-Great-Vegan-Grains-Book-Celebrate-Whole-Grains-with-More-than-100-Delicious-Plant-Based-Recipes-Includes-Soy-Free-and-Gluten-Free-Recipes-by-Celine-Steen.pdf
    • http://xiixmcuin.linkpc.net/9205206200200202/Healthy-Drink-Recipes-All-Natural-Sugar-Free-Gluten-Free-Low-Carb-Paleo-and-Vegan-Drink-Recipes-with-Max-5-Ingredients-by-Elviira-Krebber.pdf
    • http://xiixmcuin.linkpc.net/7209204204201206/100-Best-Gluten-Free-Recipes-for-Your-Vegan-Kitchen-Delicious-Smoothies-Soups-Salads-Entrees-and-Desserts-by-Kelly-Keough.pdf
    • http://xiixmcuin.linkpc.net/1201202202206200200/Untamed-by-Sayuri-Nagasaki.pdf
    • http://xiixmcuin.linkpc.net/1201202202204207201/BECAUSE-I-M-A-MAID-Episode-4-by-Sayuri-Sakai.pdf
    • http://xiixmcuin.linkpc.net/1201202202207200209/I-Still-Love-You-Even-Wake-Up-from-My-Dream-by-Sayuri-Miroku.pdf
    • http://xiixmcuin.linkpc.net/1201202202205202200/BECAUSE-I-M-A-MAID-Episode-7-The-Darkness-in-the-Heart-by-Sayuri-Sakai.pdf
    • http://xiixmcuin.linkpc.net/1201202202208201205/Otome-no-nitijou-Tokiwa-Sayuri-Lite-007-by-HoneyRabbit.pdf
    • http://xiixmcuin.linkpc.net/1201202202205209201/dutch-wife-sayuri-syasinsyuu-vol1-by-NOSTYLE.pdf
    • http://xiixmcuin.linkpc.net/1201202202208201207/Otome-no-nitijou-Tokiwa-Sayuri-Lite-008-by-HoneyRabbit.pdf
    • http://xiixmcuin.linkpc.net/1201202202208201206/Otome-no-nitijou-Tokiwa-Sayuri-Lite-004-by-HoneyRabbit.pdf
    • http://xiixmcuin.linkpc.net/1201202202208202200/Otome-no-nitijou-Tokiwa-Sayuri-Lite-002-by-HoneyRabbit.pdf
    • http://xiixmcuin.linkpc.net/9208204201/Deliciously-Ella-100-Easy-Healthy-and-Delicious-Plant-Based-Gluten-Free-Recipes-by-Ella-Woodward.pdf
    • http://xiixmcuin.linkpc.net/1208203203205203/BabyCakes-Vegan-Mostly-Gluten-Free-and-Mostly-Sugar-Free-Recipes-from-New-York-s-Most-Talked-About-Bakery-by-Erin-McKenna.pdf
    • http://xiixmcuin.linkpc.net/1201202202206200204/Transpacific-Field-of-Dreams-How-Baseball-Linked-the-United-States-and-Japan-in-Peace-and-War-by-Sayuri-Guthrie-Shimizu.pdf
    • http://xiixmcuin.linkpc.net/1200207205203206208/The-Vegan-Baker-More-Than-50-Delicious-Recipes-for-Vegan-friendly-Cakes-Cookies-Bars-and-Other-Baked-Treats-by-Dunja-Gulin.pdf
    • http://xiixmcuin.linkpc.net/1208203201206209/Isa-Does-It-Amazingly-Easy-Wildly-Delicious-Vegan-Recipes-for-Every-Day-of-the-Week-by-Isa-Chandra-Moskowitz.pdf