Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae3d0e13fbc1f42d…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 05:21:12 +01:00 Authoring application: mPDF 5.7
MD5: 148a84d59d94695285307107d724c177 SHA-1: ec3d446949c83e95b3ccef842779b25ac0791c11 SHA-256: ae3d0e13fbc1f42d452d4a0b1be5c3990eb465168b484f2f09e12e4554bcb5ad
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and embedded URLs suggest a delivery mechanism for potentially harmful content, possibly related to a phishing or content-scraping attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/5200207200200200/Coyote-America-A-Natural-and-Supernatural-History-by-Dan-Flores.pdf
    • http://xiixmcuin.linkpc.net/2205203205203206/The-Natural-History-of-Make-Believe-A-Guide-to-the-Principal-Works-of-Britain-Europe-and-America-by-John-Goldthwaite.pdf
    • http://xiixmcuin.linkpc.net/4200207209208207/Haunted-America-Star-Spangled-Supernatural-Stories-by-Marvin-Kaye.pdf
    • http://xiixmcuin.linkpc.net/5204200206205201/Coyote-Frontier-Coyote-Trilogy-3-by-Allen-M-Steele.pdf
    • http://xiixmcuin.linkpc.net/1202208205207205/Coyote-In-A-Graveyard-The-1984-Screenplay-by-The-Hippy-Coyote.pdf
    • http://xiixmcuin.linkpc.net/1202209209209209/Coyote-in-Provence-Coyote-2-by-Dianne-Harman.pdf
    • http://xiixmcuin.linkpc.net/6202208207208203/Ghosts-Apparitions-and-Poltergeists-An-Exploration-of-the-Supernatural-Through-History-by-Brian-Righi.pdf
    • http://xiixmcuin.linkpc.net/7204201201209204/The-Smithsonian-Guides-to-Natural-America-The-Heartland-by-Suzanne-Winckler.pdf
    • http://xiixmcuin.linkpc.net/2208207208202207/The-Sibold-Effect-Beyond-Science-History-Ghosts-and-the-Appalachian-Supernatural-by-John-David-Miller.pdf
    • http://xiixmcuin.linkpc.net/1204204205202204/Sahara-A-Natural-History-by-Marq-de-Villiers.pdf
    • http://xiixmcuin.linkpc.net/8202201207202200/The-History-of-Natural-Hygiene-by-Hereward-Carrington.pdf
    • http://xiixmcuin.linkpc.net/4204207206203208/The-Natural-History-of-Canterbury-by-Michael-Winterbourn.pdf
    • http://xiixmcuin.linkpc.net/6209200202207203/The-Natural-History-of-Unicorns-by-Chris-Lavers.pdf
    • http://xiixmcuin.linkpc.net/3202204208205201/The-Natural-History-of-Selborne-by-Gilbert-White.pdf
    • http://xiixmcuin.linkpc.net/5208205202205209/A-Natural-History-of-the-Romance-Novel-by-Pamela-Regis.pdf
    • http://xiixmcuin.linkpc.net/4204206203204202/The-Natural-History-of-Unicorns-by-Chris-Lavers.pdf
    • http://xiixmcuin.linkpc.net/6209207205205208/Walking-with-Dinosaurs-A-Natural-History-by-Tim-Haines.pdf
    • http://xiixmcuin.linkpc.net/7209204200206201/North-Atlantic-Biota-and-Their-History-A-Symposium-Held-at-the-University-of-Iceland-Reykjav-k-July-1962-Under-the-Auspices-of-the-University-of-Iceland-and-the-Museum-of-Natural-History-Editors-Askell-L-ve-and-Doris-L-ve-Sponsored-by-the-Nat-by-Reykjavik-Natturugripasafnid.pdf
    • http://xiixmcuin.linkpc.net/3206207202207205/The-Natural-History-of-Canadian-Mammals-by-Donna-Naughton.pdf
    • http://xiixmcuin.linkpc.net/4209204204204204/The-Natural-History-and-Antiquities-of-Selborne-by-Gilbert-White.pdf
    • http://xiixmcuin.linkpc.net/6202208207208203/Ghosts-Apparitions-and-Poltergeists-An-Exploration-of-the-Supernatural