Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0d2333b9cf4f951…

MALICIOUS

PDF

17.2 KB Created: 2019-05-07 05:36:12 +01:00 Authoring application: mPDF 5.7
MD5: a6e95d098902b75c36508ebf3d342e0e SHA-1: 147cba7718a8d9ccf64459c7f7061643b095d820 SHA-256: e0d2333b9cf4f9517e0d89e86bb121cf6444b8a6b23513c65e5b83bf08bbaaf6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'xiixmcuin.linkpc.net'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1200204204209204209/Papi-s-Bodega-by-Veronica-Chambers.pdf
    • http://xiixmcuin.linkpc.net/3204206200204200/When-Did-You-Stop-Loving-Me-by-Veronica-Chambers.pdf
    • http://xiixmcuin.linkpc.net/2205209202204204/The-Meaning-of-Michelle-16-Writers-on-the-Iconic-First-Lady-and-How-Her-Journey-Inspires-Our-Own-by-Veronica-Chambers.pdf
    • http://xiixmcuin.linkpc.net/1201207200200208202/The-Chambers-Complete-Crossword-Companion-by-Chambers-Dictionaries.pdf
    • http://xiixmcuin.linkpc.net/1201207200201206202/Chambers-Crossword-Completer---New-Edition-by-Chambers-Dictionaries.pdf
    • http://xiixmcuin.linkpc.net/1201201204204201208/Chambers-s-Edinburgh-Journal-No-453-by-Robert-Chambers.pdf
    • http://xiixmcuin.linkpc.net/1201207205203203207/Chambers-s-Edinburgh-Journal-No-418-by-Robert-Chambers.pdf
    • http://xiixmcuin.linkpc.net/2201200208209208/At-the-Far-Reaches-of-Empire-The-Life-of-Juan-Francisco-de-la-Bodega-Y-Quadra-by-Freeman-M-Tovell.pdf
    • http://xiixmcuin.linkpc.net/4208205205203209/-oku-The-Inner-Chambers-Volume-6-oku-The-Inner-Chambers-6-by-Fumi-Yoshinaga.pdf
    • http://xiixmcuin.linkpc.net/4208205205204200/-oku-The-Inner-Chambers-Volume-7-oku-The-Inner-Chambers-7-by-Fumi-Yoshinaga.pdf
    • http://xiixmcuin.linkpc.net/1200204204206207200/Papi-by-J-P-Barnaby.pdf
    • http://xiixmcuin.linkpc.net/1200204205200202208/Against-Ratzinger-by-Giacomo-Papi.pdf
    • http://xiixmcuin.linkpc.net/9201209200201201/Veronica-The-Autobiography-of-Veronica-Lake-by-Veronica-Lake.pdf
    • http://xiixmcuin.linkpc.net/1200204204206207204/I-Call-My-Thug-Papi-by-Chrissy-J.pdf
    • http://xiixmcuin.linkpc.net/1200204205200204200/Papi-How-Many-Stars-Are-in-the-Sky-by-Angel-Vigil.pdf
    • http://xiixmcuin.linkpc.net/1200204204207206209/Diego-and-Papi-to-the-Rescue-by-Wendy-Wax.pdf
    • http://xiixmcuin.linkpc.net/1200204204208208205/Queer-PAPI-Porn-Gay-Asian-Erotica-by-Joel-B-Tan.pdf
    • http://xiixmcuin.linkpc.net/7200206209200201/Jewels-of-the-Romanovs-Family-Court-by-Stefano-Papi.pdf
    • http://xiixmcuin.linkpc.net/1200204204208209200/NARUTOZUKIBUROGURYU-NARUTO-NOYOMIKATA-NARUTONOKOTOBANOCHIkARAWO-YOMIHOGUSHITEMIRU-NARUTONOYOMIKATA-by-PAPI.pdf
    • http://xiixmcuin.linkpc.net/9200207204204207/Papi-ist-ein-Abenteurer-Mami-1741---Familienroman-by-Annette-Mansdorf.pdf
    • http://xiixmcuin.linkpc.net/2201200208209208/At-the-Far-Reaches-of-Empire-The-Life-of-Juan-Francisco-de-la-Bodega-Y-Quadra-by-Freeman-M-Tov