Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7565785f7be2690…

MALICIOUS

PDF

21.7 KB Created: 2019-04-28 12:42:34 +01:00 Authoring application: mPDF 5.7
MD5: e4abc04ec309d1ab0862d6994d9e082b SHA-1: 5bbf934f031b1636b0aa695748558fde827a2f13 SHA-256: a7565785f7be26903de3c405aa64f2eab1ec0c7d460e91b3acdf002d15e8b6ed
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, many of which point to PDFs with numeric slugs in their URLs, indicative of SEO poisoning or a link farm. While the specific URLs themselves were labeled as benign, the sheer volume and pattern suggest a malicious intent to redirect users to potentially harmful content or to manipulate search engine results. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201201205209208201/Death-Lonely-and-Peculiar-A-Dr-Ray-Raether-South-Carolina-Travel-Mystery-by-Robert-C-Angel.pdf
    • http://xiixmcuin.linkpc.net/6201202208203205/Mid-South-Regional-Atlas-amp-Gazetteer-s-Kentucky-Tennessee-North-Carolina-South-Carolina-and-Virginia-Atlases-by-DeLorme-Mapping-Company.pdf
    • http://xiixmcuin.linkpc.net/8205202203205204/Journal-of-the-Commons-House-of-Assembly-of-South-Carolina-1693-by-South-Carolina-Assembly.pdf
    • http://xiixmcuin.linkpc.net/1204201206201200/The-Peculiar-Life-of-a-Lonely-Postman-by-Denis-Th-riault.pdf
    • http://xiixmcuin.linkpc.net/1200209208201204202/Lonely-Planet-s-Ultimate-Travel-Our-List-of-the-500-Best-Places-to-See-Ranked-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/5201208200202201/Sectionalism-And-Representation-In-South-Carolina-by-W-A-Schaper.pdf
    • http://xiixmcuin.linkpc.net/3203202203206204/South-Carolina-a-History-by-Walter-Edgar.pdf
    • http://xiixmcuin.linkpc.net/1207203206203/Death-of-A-Mystery-Writer-by-Robert-Barnard.pdf
    • http://xiixmcuin.linkpc.net/3200201201201203/The-Risk-Taker-Sweetheart-South-Carolina-1-by-Kira-Sinclair.pdf
    • http://xiixmcuin.linkpc.net/4202204208206202/Ghostly-Tales-from-South-Carolina-by-Kendell-Chad-Watts.pdf
    • http://xiixmcuin.linkpc.net/1200201201205202206/Beaufort-South-Carolina-A-History-by-Alexia-Jones-Helsley.pdf
    • http://xiixmcuin.linkpc.net/1200201201206206203/A-Guide-to-Historic-Beaufort-South-Carolina-by-Alexia-Jones-Helsley.pdf
    • http://xiixmcuin.linkpc.net/1201205200203201201/Killer-Files-Abduction-amp-Murder-in-South-Carolina-by-John-Humphrey.pdf
    • http://xiixmcuin.linkpc.net/3208203203208202/Thailand-Vietnam-Laos-amp-Cambodia-Travel-Atlas-by-Lonely-Planet.pdf
    • http://xiixmcuin.linkpc.net/1203208203202201/Folly-Beach-Dances---The-Infinite-Rhythms-of-a-South-Carolina-Seashore-by-Sheree-K-Nielsen.pdf
    • http://xiixmcuin.linkpc.net/6207209204206207/History-of-the-German-Settlements-and-of-the-Lutheran-Church-in-North-and-South-Carolina-by-Gotthardt-Bernheim.pdf
    • http://xiixmcuin.linkpc.net/5201208202205202/The-Work-of-Reconstruction-From-Slave-to-Wage-Laborer-in-South-Carolina-1860-1870-by-Julie-Saville.pdf
    • http://xiixmcuin.linkpc.net/5201208202201208/Unification-of-a-Slave-State-The-Rise-of-the-Planter-Class-in-the-South-Carolina-Backcountry-1760-1808-by-Rachel-N-Klein.pdf
    • http://xiixmcuin.linkpc.net/1201203207201205204/Travel-North-Carolina-Going-Native-in-the-Old-North-State-by-Carolyn-Sakowski.pdf
    • http://xiixmcuin.linkpc.net/3209205208206201/The-Angel-of-Death-Police-Snipers-amp-Hostage-Negotiators-Angel-Day-1-by-Blair-Babylon.pdf
    • http://xiixmcuin.linkpc.net/1200209208201204202/Lonely-Planet-s-Ultimate-Travel-Our-List