Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc2f0da1714f99e3…

MALICIOUS

PDF

22.7 KB Created: 2019-05-01 17:22:47 +01:00 Authoring application: mPDF 5.7
MD5: 21939603915c778549a3b6ca6c4df54c SHA-1: 8f8c225b107b7c9dbf8d75e4a2e245e61d2bfa0e SHA-256: cc2f0da1714f99e3734c4aa0819e995f2424310dd6f2ea01a2b34af48d8c33e4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDFs hosted on the domain xiixmcuin.linkpc.net. This is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201207208202202200/Freiheit-ALS-Liebe-bei-Martin-Luther-Freedom-as-Love-in-Martin-Luther-8th-International-Congress-for-Luther-Research-in-St-Paul-Minnesota-1993-Seminar-I-Referate-Papers-by-Dennis-D-Bielfeldt.pdf
    • http://xiixmcuin.linkpc.net/8204204206202203/Solus-Decalogus-Est-Aeternus-Martin-Luther-s-Complete-Antinomian-Theses-and-Disputations-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/8204204203205208/Martin-Luther-s-Ninety-Five-Theses-and-Selected-Sermons-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/3205201207204202/MLK-The-Martin-Luther-King-Jr-Tapes-Featuring-Speeches-given-by-Rev-Martin-Luther-King-Jr-by-Martin-Luther-King-Jr-.pdf
    • http://xiixmcuin.linkpc.net/1203202205204203/Martin-Luther-King-The-Essential-Box-Set-The-Landmark-Speeches-and-Sermons-of-Martin-Luther-King-Jr-by-Clayborne-Carson.pdf
    • http://xiixmcuin.linkpc.net/9203200207203201/Martin-Luther-s-Commentary-on-Galatians-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/1201207207208201207/The-Table-Talk-of-Martin-Luther-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/6204200207204203/The-Sermons-of-Martin-Luther-7-Volumes-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/9200204202203200/Von-der-Freiheit-eines-Christenmenschen-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/1201209203200200203/Von-Der-Freiheit-Eines-Christenmenschen-2-Auflage-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/2201203204200200/The-Freedom-of-a-Christian-by-Martin-Luther.pdf
    • http://xiixmcuin.linkpc.net/4202204202205207/Stride-Toward-Freedom-The-Montgomery-Story-by-Martin-Luther-King-Jr-.pdf
    • http://xiixmcuin.linkpc.net/1201207208201200208/The-Substance-of-the-Faith-Luther-s-Doctrinal-Theology-for-Today-by-Dennis-Bielfeldt.pdf
    • http://xiixmcuin.linkpc.net/9201206205204/The-Words-of-Martin-Luther-King-Jr-by-Martin-Luther-King-Jr-.pdf
    • http://xiixmcuin.linkpc.net/9201206202202/Ring-Out-Freedom-The-Voice-of-Martin-Luther-King-Jr-and-the-Making-of-the-Civil-Rights-Movement-by-Fredrik-Sunnemark.pdf
    • http://xiixmcuin.linkpc.net/1204204200201206/As-Good-as-Anybody-Martin-Luther-King-and-Abraham-Joshua-Heschel-s-Amazing-March-Toward-Freedom-by-Richard-Michelson.pdf
    • http://xiixmcuin.linkpc.net/4201205206209204/Gospel-of-Freedom-Martin-Luther-King-Jr-s-Letter-from-Birmingham-Jail-and-the-Struggle-That-Changed-a-Nation-by-Jonathan-Rieder.pdf
    • http://xiixmcuin.linkpc.net/7200202201204/Martin-s-Big-Words-The-Life-of-Dr-Martin-Luther-King-Jr-by-Doreen-Rappaport.pdf
    • http://xiixmcuin.linkpc.net/6204200206205202/A-Gift-of-Love-Sermons-from-Strength-to-Love-and-Other-Preachings-by-Martin-Luther-King-Jr-.pdf
    • http://xiixmcuin.linkpc.net/1201207207208207207/By-Faith-Alone-by-Martin-Luther.pdf