Malicious PDF — malware analysis report

Static analysis result for SHA-256 a40fc4f134e049c9…

MALICIOUS

PDF

16.7 KB Created: 2019-05-01 18:25:29 +01:00 Authoring application: mPDF 5.7
MD5: c93d4512b88a2f3ccb9506ff7a5cb802 SHA-1: 351a422caa1db612909f41e78a0e06fa9d938909 SHA-256: a40fc4f134e049c9e6d64bafaa2b69f15aff7dbcb3a4519d64b523d016b0ef1e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO spam or to distribute further malware. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8203207203200205/Black-Bob-The-Dandy-Wonder-Dog-1965-Annual-by-Jack-Prout.pdf
    • http://xiixmcuin.linkpc.net/8204209207203201/Belgian-Football-Clubs-Standard-Liege-K-A-A-Gent-Kv-Mechelen-K-R-C-Genk-Football-in-Belgium-S-Du-Pays-de-Charleroi-Lierse-S-K-by-Source-Wikipedia.pdf
    • http://xiixmcuin.linkpc.net/9204203201203207/Football-Outsiders-Almanac-2010-The-Essential-Guide-to-the-2010-NFL-and-College-Football-Seasons-by-Aaron-Schatz.pdf
    • http://xiixmcuin.linkpc.net/9206207201208205/Path-Word-A-Novel-Novel-by-Zanger-Z-iga.pdf
    • http://xiixmcuin.linkpc.net/9206207202206200/Film-Remakes-as-Ritual-and-Disguise-by-Anat-Zanger.pdf
    • http://xiixmcuin.linkpc.net/9206207201207200/Mount-Shasta-History-Legends-and-Lore-by-Michael-Zanger.pdf
    • http://xiixmcuin.linkpc.net/9206207201207207/Jerusalem-Holy-City-to-the-World-s-Religions-by-Walter-Zanger.pdf
    • http://xiixmcuin.linkpc.net/9206207202205207/Quicklet-on-It-s-a-Wonderful-Life-by-Frank-Capra-by-Elliot-Zanger.pdf
    • http://xiixmcuin.linkpc.net/9206207201206209/Film-Remakes-as-Ritual-and-Disguise-From-Carmen-to-Ripley-by-Anat-Zanger.pdf
    • http://xiixmcuin.linkpc.net/1203205208206/Jack-on-the-Tracks-Four-Seasons-of-Fifth-Grade-Jack-Henry-4-by-Jack-Gantos.pdf
    • http://xiixmcuin.linkpc.net/9201200209203208/Battle-For-Pakistan-The-Air-War-of-1965-by-John-Fricker.pdf
    • http://xiixmcuin.linkpc.net/8208209205205202/Nipper-1965-1966-by-Doug-Wright.pdf
    • http://xiixmcuin.linkpc.net/4202204204207206/The-Diaries-1931-1965-by-Dawn-Powell.pdf
    • http://xiixmcuin.linkpc.net/1208207206208202/Into-a-Black-Sun-Vietnam-1964-1965-by-Takeshi-Kaik-.pdf
    • http://xiixmcuin.linkpc.net/3206201209203206/Flying-At-Night-Poems-1965-1985-by-Ted-Kooser.pdf
    • http://xiixmcuin.linkpc.net/8207208209205209/The-Journals-Volume-I-1949-1965-by-John-Fowles.pdf
    • http://xiixmcuin.linkpc.net/1200202208204200203/Selected-Poems-1965-1973-by-Marin-Sorescu.pdf
    • http://xiixmcuin.linkpc.net/2201206201208/Paper-Trail-Selected-Prose-1965-2003-by-Richard-Howard.pdf
    • http://xiixmcuin.linkpc.net/9200208200207205/Malcolm-X-Une-vie-de-r-inventions-1925-1965-Radical-America-by-Manning-Marable.pdf
    • http://xiixmcuin.linkpc.net/4209200203209200/The-Girl-with-the-Emerald-Brooch-Growing-up-1954---1965-by-Jacqueline-Creek.pdf
    • http://xiixmcuin.linkpc.net/9206207201207200/Mo