Malicious PDF — malware analysis report

Static analysis result for SHA-256 d71e8bdf0cdb304b…

MALICIOUS

PDF

21.2 KB Created: 2019-05-02 17:48:56 +01:00 Authoring application: mPDF 5.7
MD5: 3096ee5bcee194d652e510d3148c561a SHA-1: b34cb9051e857f3812ddb4009bea7a840d5a379d SHA-256: d71e8bdf0cdb304b16a043e20bc5a93b2955620d5d9efc15b10745e2731ce2c3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier as malicious and contains a large number of external links, many of which point to other PDFs. The document body contains embedded URLs that appear to be part of a link farm, likely intended to drive traffic to potentially malicious content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/2202205201205208/A-Puppy-for-Christmas-On-the-Secretary-s-Christmas-List-The-Soldier-the-Puppy-and-Me-The-Patter-of-Paws-at-Christmas-by-Carole-Mortimer.pdf
    • http://xiixmcuin.linkpc.net/1201203205204209208/Puppy-Development-Guide---Puppy-101-for-Dog-Lovers-The-Secrets-to-Puppy-Training-Without-Force-Fear-and-Fuss-by-Tim-Carter.pdf
    • http://xiixmcuin.linkpc.net/8206207208201/Trouble-with-Puppy-Mills-Amish-Forever-A-New-Journey-4-by-Crystal-Linn.pdf
    • http://xiixmcuin.linkpc.net/3207203207200202/Christmas-Ivy-Forever-Christmas-The-Second-Season-Book-1-by-Joanne-Jaytanie.pdf
    • http://xiixmcuin.linkpc.net/2202206209204200/Forever-Love-Forever-Love-1-2-by-Megan-Smith.pdf
    • http://xiixmcuin.linkpc.net/4202202208208201/Shine-Forever-Lovesongs-3-by-Megan-Derr.pdf
    • http://xiixmcuin.linkpc.net/3207203209209201/Forever-Christmas-by-Christine-Lynxwiler.pdf
    • http://xiixmcuin.linkpc.net/5209205203202202/Chow-Chows-The-Owner-s-Guide-From-Puppy-To-Old-Age---Buying-Caring-for-Grooming-Health-Training-and-Understanding-Your-Chow-Chow-Dog-or-Puppy-by-Alex-Seymour.pdf
    • http://xiixmcuin.linkpc.net/8204209209200/A-Plain-Christmas-Amish-Forever-3-by-Roger-Rheinheimer.pdf
    • http://xiixmcuin.linkpc.net/2205202203206/The-Cowboy-s-Christmas-Surprise-Forever-Texas-9-by-Marie-Ferrarella.pdf
    • http://xiixmcuin.linkpc.net/2200207209208/Kiss-Me-Forever-Love-Me-Forever-Forever-Vampires-1-2-by-Rosemary-Laurey.pdf
    • http://xiixmcuin.linkpc.net/7208202205205208/The-Forever-War-Series-The-Forever-War-A-Separate-War-and-Forever-Free-by-Joe-Haldeman.pdf
    • http://xiixmcuin.linkpc.net/3207203202201205/Christmas-Proposals-Her-Christmas-Romeo-The-Tycoon-s-Christmas-Engagement-A-Bride-for-Christmas-by-Carole-Mortimer.pdf
    • http://xiixmcuin.linkpc.net/1207203200205208/Once-There-Was-a-Way-What-if-The-Beatles-Stayed-Together-by-Bryce-Zabel.pdf
    • http://xiixmcuin.linkpc.net/4205201202209200/I-Should-Have-Stayed-Home-by-Horace-McCoy.pdf
    • http://xiixmcuin.linkpc.net/2203207205208203/The-Children-Who-Stayed-Alone-by-Bonnie-Bess-Worline.pdf
    • http://xiixmcuin.linkpc.net/2208207207203208/The-Mother-Who-Stayed-Stories-by-Laura-Furman.pdf
    • http://xiixmcuin.linkpc.net/4206209209204204/All-a-Cowboy-Wants-for-Christmas-Waiting-for-Christmas-His-Christmas-Wish-Once-Upon-a-Frontier-Christmas-by-Judith-Stacy.pdf
    • http://xiixmcuin.linkpc.net/3203207200203206/Fractured-Fate-There-s-a-Reason-It-Stayed-Lost-by-Caja-Coyote.pdf
    • http://xiixmcuin.linkpc.net/6203206205205200/Love-Song-for-Baby-X-How-I-Stayed-Almost-Sane-on-the-Rocky-Road-to-Parenthood-by-Cheryl-Dumesnil.pdf