Malicious PDF — malware analysis report

Static analysis result for SHA-256 a94580a0e52bb6ef…

MALICIOUS

PDF

25.3 KB Created: 2019-05-02 05:39:31 +01:00 Authoring application: mPDF 5.7
MD5: 1ae6ea9c40af6a963c6a467eaa559167 SHA-1: 97f5bdf106c8be349eb9f56b01b4a70de3c59b8d SHA-256: a94580a0e52bb6ef409cd341b47cb101bc9130f7f51ebe38a28b23cfc1213b46
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this file as malicious. The embedded URLs are hosted on a dynamic DNS domain, suggesting an attempt to manipulate search engine results or distribute potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9910

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2205208203203208/The-Snark-Handbook-A-Reference-Guide-to-Verbal-Sparring-by-Lawrence-Dorfman.pdf
    • http://xiixmcuin.linkpc.net/1200203209204202203/The-Crosscultural-Language-and-Academic-Development-Handbook-A-Complete-K-12-Reference-Guide-by-Lynne-T-Diaz-Rico.pdf
    • http://xiixmcuin.linkpc.net/1200209203205209203/The-Annotated-Guide-To-Dean-Koontz-Starmount-Reference-Guide-No-14-by-Bill-Munster.pdf
    • http://xiixmcuin.linkpc.net/6208209206206200/The-St-Lawrence-Hall-Guide-from-Niagara-Falls-to-the-Saguenay-by-Montreal-St-Lawrence-Hall.pdf
    • http://xiixmcuin.linkpc.net/1201209202207206201/Menopause-and-the-Mind-The-Complete-Guide-to-Coping-with-the-Cognitive-Effects-of-Perimenopause-and-Menopause-Including-Memory-Loss-Foggy-Thinking-Verbal-Slips-by-Claire-L-Warga.pdf
    • http://xiixmcuin.linkpc.net/1201202206206209200/Ultimate-Handbook-Guide-to-Guilin-China-Travel-Guide-by-Felicia-Harrington.pdf
    • http://xiixmcuin.linkpc.net/9202209207204206/Turbo-Pascal-Program-Reference-Guide-by-H-Bomanns.pdf
    • http://xiixmcuin.linkpc.net/1200200208200201205/Reference-Guide-For-Pharmacy-Technician-Exam-by-Manan-Shroff.pdf
    • http://xiixmcuin.linkpc.net/1202209209207203/C-S-Lewis-A-Reference-Guide-1972-1988-by-Susan-Lowenberg.pdf
    • http://xiixmcuin.linkpc.net/1201202203204202201/Respiratory-Pocket-Clinical-Reference-Guide-by-Jakob-Bajraktarevic.pdf
    • http://xiixmcuin.linkpc.net/1200200208200208202/Reference-Guide-for-Pharmacy-Licensing-Exam-by-Manan-Shroff.pdf
    • http://xiixmcuin.linkpc.net/3204203209208208/The-Rough-Guide-To-Classical-Music-Rough-Guide-Music-Reference---4th-edition-by-Duncan-Clark.pdf
    • http://xiixmcuin.linkpc.net/1202202207209208/STL-Tutorial-and-Reference-Guide-C-Programming-with-the-Standard-Template-Library-by-David-R-Musser.pdf
    • http://xiixmcuin.linkpc.net/1200200208200200206/Reference-Guide-for-Pharmacy-Technician-Exam-Revised-Edition-by-Manan-Shroff.pdf
    • http://xiixmcuin.linkpc.net/6201208201202202/The-Encyclopedia-Of-Wood-Working-The-Essential-Reference-Guide-For-The-Home-Woodworker-by-Mark-Ramuz.pdf
    • http://xiixmcuin.linkpc.net/1200200208203202203/Reference-Guide-For-Pharmacy-Licensing-Exam-Questions-and-Answers-Second-Edition-for-NAPLEX-by-Manan-Shroff.pdf
    • http://xiixmcuin.linkpc.net/9208205203200200/Lady-Chatterley-s-Lover-by-D-H-Lawrence-Illustrated-Delphi-Parts-Edition-D-H-Lawrence-by-D-H-Lawrence.pdf
    • http://xiixmcuin.linkpc.net/1201202205209208206/The-Fiction-of-L-Ron-Hubbard-A-Comprehensive-Bibliography-and-Reference-Guide-to-Published-and-Selected-Unpublished-Works-by-William-J-Widder.pdf
    • http://xiixmcuin.linkpc.net/1200200208202207200/2017-2018-Edition-Reference-Guide-for-FPGEE-Management-and-Pharmacoeconomics---Over-500-Questions-and-Answers-by-Manan-Shroff.pdf
    • http://xiixmcuin.linkpc.net/1200200208203202207/2017-2018-Edition-THEORY-Reference-Guide-For-Pharmacy-Management-amp-Pharmacoeconomics-for-FPGEE-amp-NAPLEX-by-Manan-Shroff.pdf
    • http://xiixmcuin.linkpc.net/120120220620