Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6debabaccddea49…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 18:58:51 +01:00 Authoring application: mPDF 5.7
MD5: e834389d81ecf7bd6c3ffe00afadd8b8 SHA-1: 0c682d44318483b5f2b3ea5ff4ba07b0a99a7767 SHA-256: c6debabaccddea49567e770534a975feb6f7c7d9f892a7d35adc546214d8b926
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing 'PDF_SEO_LINK_FARM' suggest a malicious intent to manipulate search engine results or distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8204205207205207/These-Desired-Things-A-Collection-of-Short-Stories-Including-Breaking-Bread-with-Ayrton-Senna-by-Steve-Matchett.pdf
    • http://xiixmcuin.linkpc.net/4207205200201205/The-Life-of-Senna-The-Biography-of-Ayrton-Senna-by-Tom-Rubython.pdf
    • http://xiixmcuin.linkpc.net/8204205207207208/Ayrton-Senna-by-Ken-Wells.pdf
    • http://xiixmcuin.linkpc.net/8204205207207201/Ayrton-Senna-All-His-Races-by-Tony-Dodgins.pdf
    • http://xiixmcuin.linkpc.net/3201203205206206/New-amp-Fresh-Holiday-Stories-Wonderful-Collection-Including-Thanksgiving-Christmas-Stories-and-Many-More-by-Betty-J-Byers.pdf
    • http://xiixmcuin.linkpc.net/2206209209204203/Lies-I-Never-Told---A-Short-Collection-of-Short-Stories-by-Martin-Crosbie.pdf
    • http://xiixmcuin.linkpc.net/3202209201201202/Short-And-Simple-A-Collection-of-Short-Stories-by-R-L-Jones.pdf
    • http://xiixmcuin.linkpc.net/3201203206205200/Cute-Stories-for-Boys-amp-Girls-Hilarious-Collection-of-Short-Stories-by-Betty-J-Byers.pdf
    • http://xiixmcuin.linkpc.net/2209205209206202/Sex-and-Stupidity-A-collection-of-Short-Stories-by-K-Syrah.pdf
    • http://xiixmcuin.linkpc.net/2209208209207202/Silver-Spurs-A-Collection-of-Short-Stories-by-Lee-Crittenden.pdf
    • http://xiixmcuin.linkpc.net/2207203203200200/The-Lagoon-A-Collection-of-Short-Stories-by-Janet-Frame.pdf
    • http://xiixmcuin.linkpc.net/9201203207202/Wormwood-A-Collection-of-Short-Stories-by-Poppy-Z-Brite.pdf
    • http://xiixmcuin.linkpc.net/3203202202200209/No-Vacancies-A-Collection-of-Short-Stories-Vol-3-by-Lucien-Black.pdf
    • http://xiixmcuin.linkpc.net/1208207209206203/Hurricane-Season-A-Collection-of-Short-Stories-by-Lela-E-Buis.pdf
    • http://xiixmcuin.linkpc.net/5207202209203204/Short-Stories-The-Ultimate-Classic-Collection-by-Alphonse-Daudet.pdf
    • http://xiixmcuin.linkpc.net/6204204209203203/Annelise-and-Barney-an-A-to-Z-Collection-of-26-Short-Stories-by-Donna-L-Florack.pdf
    • http://xiixmcuin.linkpc.net/2200206201200204/Glimpses-A-Collection-of-Nightrunner-Short-Stories-by-Lynn-Flewelling.pdf
    • http://xiixmcuin.linkpc.net/2204202205204208/Afternoon-Delights-A-Collection-of-Hot-Short-Stories-by-Mickey-Miller.pdf
    • http://xiixmcuin.linkpc.net/4204204200209206/Cross-Section-a-Collection-of-Short-Stories-by-Conor-Engelbrecht.pdf
    • http://xiixmcuin.linkpc.net/8208205200205209/Ahead-of-Time-A-Collection-of-Short-Stories-by-Henry-Kuttner.pdf
    • http://xiixmcuin.linkpc.net/3202209201201202/Short-And-Simple-A-Collection-of-Sh