Malicious PDF — malware analysis report

Static analysis result for SHA-256 b684c7953709429f…

MALICIOUS

PDF

18.5 KB Created: 2019-05-06 19:05:50 +01:00 Authoring application: mPDF 5.7
MD5: 0efcce29fe75871b25936ba2044efb2e SHA-1: ec0245b20d524570000b07e441016efa2032601b SHA-256: b684c7953709429fd2ebb0d033138c333f3a7540dec04612bd2befad260f2d90
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/9207209209205205/Sullivan-s-Justice-Carolyn-Sullivan-2-by-Nancy-Taylor-Rosenberg.pdf
    • http://xiixmcuin.linkpc.net/9207209209208208/Revenge-of-Innocents-Carolyn-Sullivan-4-by-Nancy-Taylor-Rosenberg.pdf
    • http://xiixmcuin.linkpc.net/3204208207200203/You-re-Making-Me-Hate-You-A-Cantankerous-Look-at-the-Common-Misconception-That-Humans-Have-Any-Common-Sense-Left-by-Corey-Taylor.pdf
    • http://xiixmcuin.linkpc.net/7202206203206/Don-t-Hate-the-Player-Hate-the-Game-by-Katie-Ashley.pdf
    • http://xiixmcuin.linkpc.net/1200200205208203208/I-Hate-You-More-Than-Anyone-Vol-5-I-Hate-You-More-Than-Anyone-5-by-Banri-Hidaka.pdf
    • http://xiixmcuin.linkpc.net/2207206206209207/I-Hate-You-More-Than-Anyone-Vol-1-I-Hate-You-More-Than-Anyone-1-by-Banri-Hidaka.pdf
    • http://xiixmcuin.linkpc.net/9207201207201209/Describing-the-adaptive-behavior-of-children-with-Down-syndrome-who-received-early-intervention-measured-by-the-Vineland-Adaptive-Behavior-Scales-A-trend-analysis-by-Molly-Sullivan-Taylor.pdf
    • http://xiixmcuin.linkpc.net/1200202203207208204/Christmas-with-Ed-Sullivan-by-Ed-Sullivan.pdf
    • http://xiixmcuin.linkpc.net/2205209206209208/Charlie-Sullivan-and-the-Monster-Hunters-Witch-Moon-Charlie-Sullivan-and-the-Monster-Hunters-2-by-D-C-McGannon.pdf
    • http://xiixmcuin.linkpc.net/7200209208202208/The-Whole-Works-of-the-Right-Rev-Jeremy-Taylor-Worthy-Communicant-Supplement-of-Sermons-Collection-of-Offices-by-Jeremy-Taylor.pdf
    • http://xiixmcuin.linkpc.net/4209205203206209/Taylor-Davis-and-the-Clash-of-Kingdoms-Taylor-Davis-2-by-Michelle-Isenhoff.pdf
    • http://xiixmcuin.linkpc.net/3200206203203206/The-Altar-of-Hate-by-Vox-Day.pdf
    • http://xiixmcuin.linkpc.net/7209208202201206/Why-I-Hate-Canadians-by-Will-Ferguson.pdf
    • http://xiixmcuin.linkpc.net/3200206205205203/Buttons-and-Hate-by-Penelope-Sky.pdf
    • http://xiixmcuin.linkpc.net/2200209207201208/Hate-To-Love-You-by-Tijan.pdf
    • http://xiixmcuin.linkpc.net/6208200206206/Because-They-Hate-by-Brigitte-Gabriel.pdf
    • http://xiixmcuin.linkpc.net/2209201201207206/Must-Hate-The-PLAYBOY-by-notjustarandomgirl.pdf
    • http://xiixmcuin.linkpc.net/6204200207/I-Hate-Everyone-But-You-by-Gaby-Dunn.pdf
    • http://xiixmcuin.linkpc.net/2207209205203205/Days-of-Hate-Act-One-by-Ale-Kot.pdf
    • http://xiixmcuin.linkpc.net/4202206207205204/Days-of-Hate-Act-Two-by-Ale-Kot.pdf
    • http://xiixmcuin.linkpc.net/9207201207201209/Describing-the-adaptive-behavior-of-children-with-Down-syndrome-who-received-early-intervention-measured-by-the-Vineland-Adaptive-Beh