Malicious PDF — malware analysis report

Static analysis result for SHA-256 aeb542223cc56ab0…

MALICIOUS

PDF

24.7 KB Created: 2019-05-01 06:15:08 +01:00 Authoring application: mPDF 5.7
MD5: d879424699843c68887e72cc84832194 SHA-1: 39cc0dd2d8543d31917ad48c066c837b1c5cff48 SHA-256: aeb542223cc56ab0e83f7e23d8ff32255864e2c6dba0859661b1c2b05d2c3d2b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier and contains a large number of embedded external links, characteristic of SEO spam or a link farm. While the specific URLs themselves were labeled as benign, the sheer volume and the heuristic firing indicate a malicious intent to direct users to a large number of external resources. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4209205201202206/Education-and-Society-in-Late-Imperial-China-1600-1900-by-Benjamin-A-Elman.pdf
    • http://xiixmcuin.linkpc.net/1209206209206201/The-Manchu-Way-The-Eight-Banners-and-Ethnic-Identity-in-Late-Imperial-China-by-Mark-Elliott.pdf
    • http://xiixmcuin.linkpc.net/5203208207209202/Negotiated-Power-In-Late-Imperial-China-The-Zongli-Yamen-And-The-Politics-Of-Reform-by-Jennifer-Rudolph.pdf
    • http://xiixmcuin.linkpc.net/4208202202206/The-Social-Origins-of-Private-Life-A-History-of-American-Families-1600-1900-by-Stephanie-Coontz.pdf
    • http://xiixmcuin.linkpc.net/7206203207209209/Les-Universites-Francaises-Au-Moyen-Age-Education-and-Society-in-the-Middle-Ages-and-Renaissance-Vol-7-Education-and-Society-in-the-Middle-Ages-and-Renaissance-Vol-7-by-Jacques-Verger.pdf
    • http://xiixmcuin.linkpc.net/8209201205206201/Murder-Most-Russian-True-Crime-and-Punishment-in-Late-Imperial-Russia-by-Louise-McReynolds.pdf
    • http://xiixmcuin.linkpc.net/5201203202203203/Artisans-in-Early-Imperial-China-by-Anthony-Barbieri-Low.pdf
    • http://xiixmcuin.linkpc.net/5201206204202207/Imperial-Twilight-The-Opium-War-and-the-End-of-China-s-Last-Golden-Age-by-Stephen-R-Platt.pdf
    • http://xiixmcuin.linkpc.net/2200201201209203/Workers-Strikes-and-Pogroms-The-Donbass-Dnepr-Bend-in-Late-Imperial-Russia-1870-1905-by-Charters-Wynn.pdf
    • http://xiixmcuin.linkpc.net/9208202204204207/Investigation-and-Conservation-of-East-Asian-Cabinets-in-Imperial-Residences-1700-1900-Lacquerware-amp-Porcelain-Conference-2013-Postprints-by-Tatjana-Bayerova.pdf
    • http://xiixmcuin.linkpc.net/9207209204202204/Politics-and-Society-in-Imperial-Rome-by-Aloys-Winterling.pdf
    • http://xiixmcuin.linkpc.net/9205204201204202/Women-Shall-Not-Rule-Imperial-Wives-and-Concubines-in-China-from-Han-to-Liao-by-Keith-McMahon.pdf
    • http://xiixmcuin.linkpc.net/5200206206201207/Culture-Power-and-the-State-Rural-North-China-1900-1942-by-Prasenjit-Duara.pdf
    • http://xiixmcuin.linkpc.net/2201207204209208/The-Boxer-Rebellion-The-Dramatic-Story-of-China-s-War-on-Foreigners-that-Shook-the-World-in-the-Summer-of-1900-by-Diana-Preston.pdf
    • http://xiixmcuin.linkpc.net/3204209206203208/Modernity-and-Self-Identity-Self-and-Society-in-the-Late-Modern-Age-by-Anthony-Giddens.pdf
    • http://xiixmcuin.linkpc.net/5201203202204209/The-World-of-Thought-in-Ancient-China-by-Benjamin-I-Schwartz.pdf
    • http://xiixmcuin.linkpc.net/1200201203209206205/A-Society-Without-Fathers-or-Husbands-The-Na-of-China-by-Cai-Hua.pdf
    • http://xiixmcuin.linkpc.net/2205207208202206/The-Rise-of-Respectable-Society-A-Social-History-of-Victorian-Britain-1830-1900-by-Francis-Michael-Longstreth-Thompson.pdf
    • http://xiixmcuin.linkpc.net/1201201201209207208/China-s-National-Minority-Education-Culture-Schooling-and-Development-by-Regie-Stites.pdf
    • http://xiixmcuin.linkpc.net/1201205201203200/Jewish-Education-and-Society-in-the-High-Middle-Ages-by-Ephraim-Kanarfogel.pdf
    • http://xiixmcuin.linkpc.net/7206203207209209/Les-Universites-Francaises-Au-Moyen-Age-Education-and-Society-in-the-Middle-Ages-and-Renaissance-Vol-7-Education-and-Society-in-the-Middle-Ages-and-Renaissance-Vol-7