Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4587513d1b6783c…

MALICIOUS

PDF

18.2 KB Created: 2019-05-04 13:54:12 +01:00 Authoring application: mPDF 5.7
MD5: bd06051cb05cef080cad7ff6abd75859 SHA-1: 09d07bbc6d04561a5b91992690e5753c2cd07f4f SHA-256: c4587513d1b6783cbdc96022f6969f7c19e1a57df91ddfa2ebd2c5ed78f57a40
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various PDF documents. While the specific intent of these links is unclear without further analysis of the linked content, the sheer volume and the heuristic firing suggest a malicious attempt to manipulate search results or distribute unwanted content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2205205202204200/Gideon-Lincecum-s-Sword-Civil-War-Letters-from-the-Texas-Home-Front-by-Jerry-Bryan-Lincecum.pdf
    • http://xiixmcuin.linkpc.net/7209201208207200/The-North-Fights-the-Civil-War-The-Home-Front-by-J-Matthew-Gallman.pdf
    • http://xiixmcuin.linkpc.net/2205205204204206/Soldier-Songs-and-Home-Front-Ballads-of-the-Civil-War-by-Irwin-Silber.pdf
    • http://xiixmcuin.linkpc.net/1208206209203209/Gideon-s-Sword-Gideon-Crew-1-by-Douglas-Preston.pdf
    • http://xiixmcuin.linkpc.net/8207208204201200/Voices-of-War-Stories-of-Service-from-the-Home-Front-and-the-Front-Lines-by-Tom-Wiener.pdf
    • http://xiixmcuin.linkpc.net/8201202203204204/Front-Row-by-Rebekah-N-Bryan.pdf
    • http://xiixmcuin.linkpc.net/4204202208205200/Civil-War-Front-Line-by-Paul-Jenkins.pdf
    • http://xiixmcuin.linkpc.net/2205203203201200/Civil-War-Front-Line-Vol-1-by-Paul-Jenkins.pdf
    • http://xiixmcuin.linkpc.net/1204203203200202/Civil-War-Front-Line-Vol-2-by-Paul-Jenkins.pdf
    • http://xiixmcuin.linkpc.net/1204203203203209/Civil-War-Front-Line-Book-2-by-Paul-Jenkins.pdf
    • http://xiixmcuin.linkpc.net/1204203203207205/Civil-War-Front-Line-Book-1-by-Paul-Jenkins.pdf
    • http://xiixmcuin.linkpc.net/4200204202200205/Front-Row-Anna-Wintour-The-Cool-Life-and-Hot-Times-of-Vogue-s-Editor-in-Chief-by-Jerry-Oppenheimer.pdf
    • http://xiixmcuin.linkpc.net/2209202209207200/The-Hand-That-Bears-the-Sword-Trophy-Chase-Trilogy-2-by-George-Bryan-Polivka.pdf
    • http://xiixmcuin.linkpc.net/2205205202207203/Songs-and-Stories-of-Civil-War-by-Jerry-Silverman.pdf
    • http://xiixmcuin.linkpc.net/1206207207208208/Freedom-Riders-John-Lewis-and-Jim-Zwerg-on-the-Front-Lines-of-the-Civil-Rights-Movement-by-Ann-Bausum.pdf
    • http://xiixmcuin.linkpc.net/6204207208205200/Sentimental-Journey-Home-Front-1-by-Barbara-Bretton.pdf
    • http://xiixmcuin.linkpc.net/2205205202201204/Lone-Star-Blue-and-Gray-Essays-on-Texas-in-the-Civil-War-by-Ralph-A-Wooster.pdf
    • http://xiixmcuin.linkpc.net/1207202208208208/Blue-Texas-The-Making-of-a-Multiracial-Democratic-Coalition-in-the-Civil-Rights-Era-by-Max-Krochmal.pdf
    • http://xiixmcuin.linkpc.net/4203202202207201/The-Home-Front-Civilian-Life-in-World-War-One-by-Peter-G-Cooksley.pdf
    • http://xiixmcuin.linkpc.net/2209206209200208/Hostile-Home-Front-Black-Ops-Brotherhood-2-by-Bella-Juarez.pdf
    • http://xiixmcuin.linkpc.net/4204