Malicious PDF — malware analysis report

Static analysis result for SHA-256 aaef6969c2987584…

MALICIOUS

PDF

12.8 KB Created: 2019-05-02 17:27:17 +01:00 Authoring application: mPDF 5.7
MD5: f743d45dcc9b182a6a60e3e3956e9d19 SHA-1: 15eb577b2fe4ca72b1eb38d2c7b4fa9aaa657c38 SHA-256: aaef6969c2987584e2d34f4dbe7a1a91bddcc76a04524ae6530e747dcee1b66f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on the `xiixmcuin.linkpc.net` domain. While the individual links are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm or SEO spamming operation, which can be a precursor to malicious activity. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8905

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkp
    • http://xiixmcuin.linkpc.net/3208209204208202/Asher-s-War-Asher-Benson-3-by-Jason-Brant.pdf
    • http://xiixmcuin.linkpc.net/1201204207200208201/Madness-Asher-Benson-2-by-Jason-Brant.pdf
    • http://xiixmcuin.linkpc.net/1201204206209202208/Asher-s-Invention-Asher-Quigley-1-by-Coleen-Kwan.pdf
    • http://xiixmcuin.linkpc.net/1209205205206209/Asher-s-Out-The-Asher-Trilogy-3-by-Elizabeth-Wheeler.pdf
    • http://xiixmcuin.linkpc.net/1201204207200207208/Asher-And-The-Threesome-Asher-2-by-Zoe-Nichols.pdf
    • http://xiixmcuin.linkpc.net/4205209209202209/The-Future-of-Us-by-Jay-Asher.pdf
    • http://xiixmcuin.linkpc.net/3208203206202207/The-Question-by-Jane-Asher.pdf
    • http://xiixmcuin.linkpc.net/6201200205204203/The-Parasite-by-Neal-L-Asher.pdf
    • http://xiixmcuin.linkpc.net/1200206209209205/Thirteen-Reasons-Why-by-Jay-Asher.pdf
    • http://xiixmcuin.linkpc.net/1205204201206206/My-Name-Is-Asher-Lev-by-Chaim-Potok.pdf
    • http://xiixmcuin.linkpc.net/1206207205200208/Burning-Ember-Eternals-1-by-Evi-Asher.pdf
    • http://xiixmcuin.linkpc.net/8206201201206/The-Gift-of-Asher-Lev-by-Chaim-Potok.pdf
    • http://xiixmcuin.linkpc.net/8206206200204/Orbus-Spatterjay-3-by-Neal-Asher.pdf
    • http://xiixmcuin.linkpc.net/1206200207207201/Orbus-Spatterjay-3-by-Neal-Asher.pdf
    • http://xiixmcuin.linkpc.net/2207206204203208/Days-Gone-Bad-Vesik-1-by-Eric-R-Asher.pdf
    • http://xiixmcuin.linkpc.net/4202204207209208/War-Factory-Transformation-2-by-Neal-Asher.pdf
    • http://xiixmcuin.linkpc.net/1204206207204207/Paths-The-Killers-2-by-Brynne-Asher.pdf
    • http://xiixmcuin.linkpc.net/1201204207202201205/The-Engineer-Reconditioned-by-Neal-Asher.pdf
    • http://xiixmcuin.linkpc.net/9203204201205/Why-the-World-Sucks-and-What-We-Can-Do-About-It-by-B-Regan-Asher.pdf
    • http://xiixmcuin.linkpc.net/1204206208208205/Vines-The-Killers-1-by-Brynne-Asher.pdf