Malicious PDF — malware analysis report

Static analysis result for SHA-256 a387c4705dadafb1…

MALICIOUS

PDF

17.2 KB Created: 2019-05-01 18:53:19 +01:00 Authoring application: mPDF 5.7
MD5: ad54958bdab337ca341b1bb7c5e21a35 SHA-1: 99a7c05095978d67798e8e89468aaa14328a2778 SHA-256: a387c4705dadafb1530df59f0277b899d0e9f5f93d977dab5038ed9de857af87
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, hosted on a dynamic DNS domain. This behavior is indicative of a link farm or a redirection scheme designed to drive traffic to potentially malicious content. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4208201208206205/P-I-Penguin-and-the-Case-of-the-Christmas-Lights-P-I-Penguin-Specials-Book-1-by-Bec-J-Smith.pdf
    • http://xiixmcuin.linkpc.net/8208205203203201/Tovi-the-Penguin-Goes-Away-for-Christmas-by-Janina-Rossiter.pdf
    • http://xiixmcuin.linkpc.net/4200205200200202/The-Penguin-State-of-the-Middle-East-Atlas-Completely-Revised-and-Updated-Third-Edition-by-Dan-Smith.pdf
    • http://xiixmcuin.linkpc.net/4201204201202204/The-Penguin-Book-of-the-Sonnet-by-Phillis-Levin.pdf
    • http://xiixmcuin.linkpc.net/4203207204200200/Amazonian-Penguin-Book-of-New-Womens-Tra-by-Dea-Birkett.pdf
    • http://xiixmcuin.linkpc.net/1209204202208206/The-Penguin-Book-of-First-World-War-Poetry-by-Jon-Silkin.pdf
    • http://xiixmcuin.linkpc.net/2201208209204205/The-Penguin-Book-of-Vampire-Stories-by-Alan-Ryan.pdf
    • http://xiixmcuin.linkpc.net/4205208202203208/The-Penguin-Book-of-First-World-War-Poetry-by-George-Walter.pdf
    • http://xiixmcuin.linkpc.net/3202205203207207/The-New-Penguin-Book-of-Scottish-Short-Stories-by-Ian-Murray.pdf
    • http://xiixmcuin.linkpc.net/4205209205208201/The-Penguin-Book-of-Australian-Verse-by-Harry-Heseltine.pdf
    • http://xiixmcuin.linkpc.net/3205202207202202/The-Penguin-Book-of-Caribbean-Short-Stories-by-E-A-Markham.pdf
    • http://xiixmcuin.linkpc.net/4201204201203200/The-Penguin-Book-of-Irish-Fiction-by-Colm-T-ib-n.pdf
    • http://xiixmcuin.linkpc.net/3202207206207209/The-Second-Penguin-Book-of-English-Short-Stories-by-Christopher-Dolley.pdf
    • http://xiixmcuin.linkpc.net/3202207206206204/The-New-Penguin-Book-of-Welsh-Short-Stories-by-Alun-Richards.pdf
    • http://xiixmcuin.linkpc.net/4205208209204200/The-Penguin-Book-of-Modern-African-Poetry-by-Gerald-Moore.pdf
    • http://xiixmcuin.linkpc.net/7208204209202202/Cowboys-Indians-and-Commuters-The-Penguin-Book-of-New-American-Voices-by-Jay-McInerney.pdf
    • http://xiixmcuin.linkpc.net/7204201202207/The-Penguin-Book-Birds-In-Suits-2006-Publication-by-Mark-Norman.pdf
    • http://xiixmcuin.linkpc.net/7204203208209207/Penguin-Puzzle-The-Magic-School-Bus-Chapter-Book-8-by-Judith-Bauer-Stamper.pdf
    • http://xiixmcuin.linkpc.net/4201204206204204/The-Penguin-Lessons-by-Tom-Michell.pdf
    • http://xiixmcuin.linkpc.net/6203209208203/Penguin-Island-by-Anatole-France.pdf