Malicious PDF — malware analysis report

Static analysis result for SHA-256 a159da6cb466ceca…

MALICIOUS

PDF

20.0 KB Created: 2019-05-05 16:49:42 +01:00 Authoring application: mPDF 5.7
MD5: bc03acb17db7387d48febadd4a104120 SHA-1: 38d910027d2ee93ebe3975e2cea8a12e64989901 SHA-256: a159da6cb466ceca78fbede07fdafc753233dce68913e59677877fb94ecfe096
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a lure to a malicious site, as flagged by the PDF_SEO_LINK_FARM heuristic. While the individual linked PDFs are currently marked as benign, the overall structure and the ML classifier's high confidence score suggest a malicious intent, likely to direct users to potentially harmful content or further stages of an attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5205202206207202/Milo-s-First-Christmas-by-Lynette-Chambers.pdf
    • http://xiixmcuin.linkpc.net/3205208207202207/Chasing-Rainbows-1-by-Lynette-Chambers.pdf
    • http://xiixmcuin.linkpc.net/8200204201208206/Milo-and-Kumo-and-The-Little-Chick-Milo-and-Kumo-s-Caribbean-Adventures-Book-1-by-Freyja-Gata.pdf
    • http://xiixmcuin.linkpc.net/1201207200200208202/The-Chambers-Complete-Crossword-Companion-by-Chambers-Dictionaries.pdf
    • http://xiixmcuin.linkpc.net/1201207200201206202/Chambers-Crossword-Completer---New-Edition-by-Chambers-Dictionaries.pdf
    • http://xiixmcuin.linkpc.net/1201207205203203207/Chambers-s-Edinburgh-Journal-No-418-by-Robert-Chambers.pdf
    • http://xiixmcuin.linkpc.net/1201201204204201208/Chambers-s-Edinburgh-Journal-No-453-by-Robert-Chambers.pdf
    • http://xiixmcuin.linkpc.net/5207201201201202/Milo-Manara-s-Odysseys-Of-Giuseppe-Bergman-by-Milo-Manara.pdf
    • http://xiixmcuin.linkpc.net/3207203202201205/Christmas-Proposals-Her-Christmas-Romeo-The-Tycoon-s-Christmas-Engagement-A-Bride-for-Christmas-by-Carole-Mortimer.pdf
    • http://xiixmcuin.linkpc.net/4208205205204200/-oku-The-Inner-Chambers-Volume-7-oku-The-Inner-Chambers-7-by-Fumi-Yoshinaga.pdf
    • http://xiixmcuin.linkpc.net/4208205205203209/-oku-The-Inner-Chambers-Volume-6-oku-The-Inner-Chambers-6-by-Fumi-Yoshinaga.pdf
    • http://xiixmcuin.linkpc.net/4206209209204204/All-a-Cowboy-Wants-for-Christmas-Waiting-for-Christmas-His-Christmas-Wish-Once-Upon-a-Frontier-Christmas-by-Judith-Stacy.pdf
    • http://xiixmcuin.linkpc.net/3207203204201205/The-Christmas-Brides-A-McKettrick-Christmas-A-Creed-Country-Christmas-McKettricks-10-Montana-Creeds-4-by-Linda-Lael-Miller.pdf
    • http://xiixmcuin.linkpc.net/5200202209200203/White-Christmas-Bloody-Christmas-Finally-the-True-Story-of-the-Lawson-Family-Murders-of-Christmas-Day-1929-by-M-Bruce-Jones.pdf
    • http://xiixmcuin.linkpc.net/9200200204203200/The-Girl-Who-Saved-Christmas-A-Boy-Called-Christmas-Father-Christmas-and-Me-by-Matt-Haig.pdf
    • http://xiixmcuin.linkpc.net/1200202204205209206/Christmas-Eve-and-Christmas-Day-Ten-Christmas-Stories-by-Edward-Everett-Hale.pdf
    • http://xiixmcuin.linkpc.net/3205208201203208/Believe-by-Lynette-Ferreira.pdf
    • http://xiixmcuin.linkpc.net/1208209209203/Tactical-Pursuit-by-Lynette-Mae.pdf
    • http://xiixmcuin.linkpc.net/3202207209206206/ForNever-by-Lynette-Ferreira.pdf
    • http://xiixmcuin.linkpc.net/3205203204203205/Wishful-Thinking-by-Lynette-Sofras.pdf
    • http://xiixmcuin.linkpc.net/3207203202201205/Christmas-Proposals-Her-Christmas-Romeo-The-Tycoon-s-Christmas