Malicious PDF — malware analysis report

Static analysis result for SHA-256 de20e22620608ef9…

MALICIOUS

PDF

15.9 KB Created: 2019-04-30 04:43:05 +01:00 Authoring application: mPDF 5.7
MD5: 9fdda09eda4f8b22c82ddef98c504059 SHA-1: 07177e3c82378d3bc5f3e5ae3e954f8ac27f8fea SHA-256: de20e22620608ef970fbb5a1f591c93b1349a0fbdf8a337d472b7e2c52e39780
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links, such as http://xiixmcuin.linkpc.net/4205209200200205/Chase-Tinker-and-the-House-of-Magic-Chase-Tinker-1-by-Malia-Ann-Haberman.pdf, are likely intended to direct users to malicious websites or for SEO spam purposes. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4205209200200205/Chase-Tinker-and-the-House-of-Magic-Chase-Tinker-1-by-Malia-Ann-Haberman.pdf
    • http://xiixmcuin.linkpc.net/1200207209203205/Chase-Tinker-and-the-House-of-Magic-Chase-Tinker-1-by-Malia-Ann-Haberman.pdf
    • http://xiixmcuin.linkpc.net/2207208205200208/Chase-of-a-Lifetime-Chase-Series-1-by-Ryan-Field.pdf
    • http://xiixmcuin.linkpc.net/3203204206207203/The-Chase-Volume-1-The-Chase-1-by-Jessica-Wood.pdf
    • http://xiixmcuin.linkpc.net/3203206207208205/The-Chase-Volume-2-The-Chase-2-by-Jessica-Wood.pdf
    • http://xiixmcuin.linkpc.net/3209200205201200/The-Chase-Volume-4-The-Chase-4-by-Jessica-Wood.pdf
    • http://xiixmcuin.linkpc.net/3203203200202206/Tinker-Elfhome-1-by-Wen-Spencer.pdf
    • http://xiixmcuin.linkpc.net/8200201205203202/Tinker-No-More-by-John-Moccia.pdf
    • http://xiixmcuin.linkpc.net/9209209209209207/Cursed-by-Magic-by-Deanna-Chase.pdf
    • http://xiixmcuin.linkpc.net/5207208204205205/The-Tinker-Of-Toledo-by-Nellie-McCaslin.pdf
    • http://xiixmcuin.linkpc.net/4209203207206202/The-Widow-s-Warning-by-Jamie-Tinker.pdf
    • http://xiixmcuin.linkpc.net/1202203207200208/Tinker-s-Plague-by-Stephen-B-Pearl.pdf
    • http://xiixmcuin.linkpc.net/7206203206208202/Rebel-Skyforce-Mad-Tinker-Chronicles-2-by-J-S-Morin.pdf
    • http://xiixmcuin.linkpc.net/7206203206209202/World-Ripper-War-Mad-Tinker-Chronicles-3-by-J-S-Morin.pdf
    • http://xiixmcuin.linkpc.net/3205205208200202/Magnus-Chase-and-the-Hammer-of-Thor-Magnus-Chase-and-the-Gods-of-Asgard-2-by-Rick-Riordan.pdf
    • http://xiixmcuin.linkpc.net/8203204203209/Magnus-Chase-and-the-Hammer-of-Thor-Magnus-Chase-and-the-Gods-of-Asgard-2-by-Rick-Riordan.pdf
    • http://xiixmcuin.linkpc.net/4209201207204204/Influential-Magic-Crescent-City-Fae-1-by-Deanna-Chase.pdf
    • http://xiixmcuin.linkpc.net/3203204209206200/Tinker-Tailor-Soldier-Spy-The-Karla-Trilogy-1-by-John-le-Carr-.pdf
    • http://xiixmcuin.linkpc.net/5201200206207207/A-Tinker-and-a-Poor-Man-John-Bunyan-and-His-Church-1628-88-by-Christopher-Hill.pdf
    • http://xiixmcuin.linkpc.net/4205203207208203/Tinker-Tailor-Soldier-Spy-The-Honourable-Schoolboy-and-Smiley-s-People-by-John-le-Carr-.pdf
    • http://xiixmcuin.linkpc.net/7206203206209202/World-Ripper-War-Mad-Tinker-Chronicles-3-by-J