Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb53ab66fccfcbbb…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 02:07:15 +01:00 Authoring application: mPDF 5.7
MD5: c4029708184f28f5d6aa16956476e344 SHA-1: d95a4017832ca511df2e69d66a64c66101022d59 SHA-256: cb53ab66fccfcbbba39055e2ba5ff530c0c37df9a85fed3968c11d0cccf425fd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified as a link farm. The primary heuristic indicates a mass of external PDF links, suggesting a tactic to manipulate search engine results or distribute further content. While no scripts were extracted, the sheer volume of links and the ML classifier's high confidence point to a malicious intent, likely related to SEO spam or content distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200205205201200203/The-Viscount-s-Sweet-Temptation-by-Aileen-Fish.pdf
    • http://xiixmcuin.linkpc.net/1200205204209209203/Outcast-Apocalyptia-1-by-Aileen-Fish.pdf
    • http://xiixmcuin.linkpc.net/6203206208207208/The-Incorrigible-Mr-Lumley-Bridgethorpe-Brides-2-by-Aileen-Fish.pdf
    • http://xiixmcuin.linkpc.net/1200205205200202206/Earl-of-Basingstoke-Wicked-Earls-Club-5-by-Aileen-Fish.pdf
    • http://xiixmcuin.linkpc.net/1200205205201200205/Christmas-in-White-Oak-Small-Town-Sweethearts-Book-3-by-Aileen-Fish.pdf
    • http://xiixmcuin.linkpc.net/4207209203203205/Sweet-Temptation-by-Anara-Bella.pdf
    • http://xiixmcuin.linkpc.net/2206207207207200/Sweet-Temptation-Men-of-Honor-2-by-K-C-Lynn.pdf
    • http://xiixmcuin.linkpc.net/4206200208201200/Sweet-Temptation-by-Lucy-Diamond.pdf
    • http://xiixmcuin.linkpc.net/3208207202201204/The-Sweet-Temptation-of-Whiskey-by-Charlene-M-Martin.pdf
    • http://xiixmcuin.linkpc.net/2208203200207206/Sweet-Temptation-Wicked-4-by-Lily-Graison.pdf
    • http://xiixmcuin.linkpc.net/1201206209207207206/Fish---Noch-mehr-Fish---F-r-immer-Fish-Dreimal-ungew-hnliche-Motivation-in-einem-Band-by-Stephen-C-Lundin.pdf
    • http://xiixmcuin.linkpc.net/2207201200201202/The-Naked-Viscount---Viscount-yang-Telanjang-Naked-Nobility-5-by-Sally-MacKenzie.pdf
    • http://xiixmcuin.linkpc.net/7204203207203202/One-Fish-Two-Fish-Red-Fish-Blue-Fish-by-Dr-Seuss.pdf
    • http://xiixmcuin.linkpc.net/8206202205207206/One-Fish-Two-Fish-Red-Fish-Blue-Fish-by-Dr-Seuss.pdf
    • http://xiixmcuin.linkpc.net/7201200202209203/Temptation-at-Work-An-Erotic-Short-Story-Temptation-in-Spring-Grove-Book-1-by-Taiden-Dashner-Gabaldon.pdf
    • http://xiixmcuin.linkpc.net/3200207204208207/Twelve-Days-of-Temptation-Temptation-1-by-Ruth-Cardello.pdf
    • http://xiixmcuin.linkpc.net/1207204209206201/Within-Temptation-Sons-of-Temptation-1-by-Tanya-Holmes.pdf
    • http://xiixmcuin.linkpc.net/9204207205204/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1206207207201207/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf
    • http://xiixmcuin.linkpc.net/1202202202206201/Gould-s-Book-of-Fish-A-Novel-in-Twelve-Fish-by-Richard-Flanagan.pdf