Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5af5814be847b89…

MALICIOUS

PDF

21.8 KB Created: 2019-05-02 01:21:54 +01:00 Authoring application: mPDF 5.7
MD5: ceb489bb54c1f93b002f2bad55470641 SHA-1: 05a14a0ff9e7bdd239eecb41411ba24e120d8625 SHA-256: a5af5814be847b89227488f2c737c171c43b3275f10a1c0c9894828bfebcde14
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded links to external PDFs hosted on the domain xiixmcuin.linkpc.net. This is indicative of a link farm or SEO poisoning tactic, designed to drive traffic to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5200202205209200/Elijah-s-Angel-A-Story-for-Chanukah-and-Christmas-by-Michael-J-Rosen.pdf
    • http://xiixmcuin.linkpc.net/3206205200209203/The-Max-Lucado-Christmas-Collection-An-Angel-s-Story-The-Christmas-Candle-The-Christmas-Child-by-Max-Lucado.pdf
    • http://xiixmcuin.linkpc.net/2208207209208202/The-Angel-Doll-A-Christmas-Story-by-Jerry-Bledsoe.pdf
    • http://xiixmcuin.linkpc.net/7205209203203203/Elijah-in-Jerusalem-by-Michael-D-O-39-Brien.pdf
    • http://xiixmcuin.linkpc.net/5200202209200203/White-Christmas-Bloody-Christmas-Finally-the-True-Story-of-the-Lawson-Family-Murders-of-Christmas-Day-1929-by-M-Bruce-Jones.pdf
    • http://xiixmcuin.linkpc.net/4209208208209201/Poems-for-the-Very-Young-by-Michael-Rosen.pdf
    • http://xiixmcuin.linkpc.net/7203206206206200/Elijah-Deville-in-Judged-Worthy-of-Death-Elijah-Deville-Mystery-Series-Book-2-by-J-R-Diestelkamp.pdf
    • http://xiixmcuin.linkpc.net/4209209200209205/Mind-Your-Own-Business-Picture-Books-by-Michael-Rosen.pdf
    • http://xiixmcuin.linkpc.net/4203204206205209/101-Damnations-The-Humorists-Tour-of-Personal-Hells-by-Michael-J-Rosen.pdf
    • http://xiixmcuin.linkpc.net/4201205200201206/Dragons-Hate-to-Be-Discreet-A-Story-by-Winifred-Rosen.pdf
    • http://xiixmcuin.linkpc.net/7203205203200202/Remains-Silent-Jake-Rosen-amp-Manny-Manfreda-1-by-Michael-Baden.pdf
    • http://xiixmcuin.linkpc.net/4204200201203206/Bananas-in-My-Ears-A-Collection-of-Nonsense-Stories-Poems-Riddles-amp-Rhymes-by-Michael-Rosen.pdf
    • http://xiixmcuin.linkpc.net/5203202205202204/A-Christmas-Carol-In-Prose-Being-a-Ghost-Story-of-Christmas-by-Charles-Dickens.pdf
    • http://xiixmcuin.linkpc.net/7202205208202205/A-Christmas-Carol-in-Prose-Being-A-Ghost-Story-of-Christmas-by-Charles-Dickens.pdf
    • http://xiixmcuin.linkpc.net/7209203204202207/Christmas-Story-Part-2-The-Ugly-Preparation-Before-Christmas-with-3D-Art-by-Koffi-Amouzouvi.pdf
    • http://xiixmcuin.linkpc.net/7206202202207202/A-Christmas-Carol-A-Ghost-Story-of-Christmas-Illustrated-by-Charles-Dickens.pdf
    • http://xiixmcuin.linkpc.net/7209203204202205/Christmas-Story-Part-1-Everyday-Like-Christmas-by-Koffi-Amouzouvi.pdf
    • http://xiixmcuin.linkpc.net/1200207208203201200/DIE-MICHAEL-CROMER-M-NCHEN-STORY-Die-MCM-Story-Von-Haien-umgeben-und-von-Neidern-hintergangen---Ein-detailliert-geplanter-Ruin-by-Michael-Cromer.pdf
    • http://xiixmcuin.linkpc.net/5203201202209204/A-CHRISTMAS-CAROL-In-Prose-BEING-A-GHOST-STORY-OF-CHRISTMAS-With-68-original-manuscript-pages-with-1843-and-1905-edition-illustrations-by-Charles-Dickens.pdf
    • http://xiixmcuin.linkpc.net/9205204209/Christmas-Angel-by-Eli-Easton.pdf