Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0d1cd0bc5ffa98b…

MALICIOUS

PDF

18.4 KB Created: 2019-05-01 19:51:37 +01:00 Authoring application: mPDF 5.7
MD5: e49796851e9bbe9553995bbbcf623a8a SHA-1: 6bbbdd7a3b8cfec8293c776b87a81eaf68765e53 SHA-256: e0d1cd0bc5ffa98bb93f3fa0e1ad8eb35447a78d2b4b196861db0490f3222158
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a lure to a large collection of potentially malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8209208203/Unsheltered-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/2205207200202206/The-Lacuna-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/4204203209201204/Flight-Behaviour-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/3203202208200/Animal-Dreams-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/1209204207201202/The-Poisonwood-Bible-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/2202207209203209/Flight-Behavior-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/1201200202203202206/The-Poisonwood-Bible-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/1206209202208206/Animal-Dreams-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/4207205200205206/Animal-Vegetable-Miracle-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/7203201209203200/Les-Yeux-dans-les-arbres-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/7203201209203202/Les-Cochons-au-paradis-Rivages-Poche-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/2202206203202202/Animal-Vegetable-Miracle-A-Year-of-Food-Life-by-Barbara-Kingsolver.pdf
    • http://xiixmcuin.linkpc.net/1200203209208200/Barbara-Kingsolver-s-The-Poisonwood-Bible-A-Reader-s-Guide-by-Linda-Wagner-Martin.pdf
    • http://xiixmcuin.linkpc.net/6209201201202/Waking-Up-in-Heaven-A-True-Story-of-Brokenness-Heaven-and-Life-Again-by-Crystal-McVea.pdf
    • http://xiixmcuin.linkpc.net/3203200201202/Heaven-is-for-Real-A-Little-Boy-s-Astounding-Story-of-His-Trip-to-Heaven-and-Back-by-Todd-Burpo.pdf
    • http://xiixmcuin.linkpc.net/2201201206203/On-The-Way-To-Heaven-She-Was-Sent-From-Heaven-To-Save-A-Marriage-Made-In-Hell-by-Tina-Wainscott.pdf
    • http://xiixmcuin.linkpc.net/8208201204207201/My-View-from-Heaven-A-Boy-s-Story-of-His-Journey-to-Heaven-and-the-Purpose-of-Life-on-Earth-by-Sarina-Baptista.pdf
    • http://xiixmcuin.linkpc.net/2206203209205209/Flight-to-Heaven-A-Plane-Crash-a-Lone-Survivor-a-Journey-to-Heaven--And-Back-by-Dale-Black.pdf
    • http://xiixmcuin.linkpc.net/4203206207206209/To-Heaven-and-Back-A-Doctor-s-Extraordinary-Account-of-Her-Death-Heaven-Angels-and-Life-Again-A-True-Story-by-Mary-C-Neal.pdf
    • http://xiixmcuin.linkpc.net/4208203209206207/Heaven-Sent-Heaven-s-Rejects-MC-1-by-Avelyn-Paige.pdf
    • http://xiixmcuin.linkpc.net/6209201201202/Waking-Up-in-Heaven-A-True-Story-of-Brokenness-Heaven-and-Life-Again-by-Crystal-Mc