Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8ac0771e30c168d…

MALICIOUS

PDF

14.7 KB Created: 2019-04-30 04:06:34 +01:00 Authoring application: mPDF 5.7
MD5: cb6b22252274d2d4adc3cbf58efd7537 SHA-1: c90e2529f8119e320ab5e1a7e02d8f9feb10c83d SHA-256: e8ac0771e30c168d6210c6b06e6bc1e9181dbc697ea9f46b1cf82c659db97f39
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, forming a link farm, which is a common technique for SEO poisoning or distributing malicious content. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with 21 external links, predominantly hosted on 'xiixmcuin.linkpc.net'. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4205201203204200/She-Can-Kill-She-Can-5-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2202204205/She-Can-Kill-She-Can-5-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2205208202205203/He-Can-Fall-She-Can-4-5-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2204209200204209/She-Can-Hide-She-Can-4-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2200205205205206/Midnight-Betrayal-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/3201206207202202/Hour-of-Need-Scarlet-Falls-1-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/7202206202205208/Her-Last-Goodbye-Morgan-Dane-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/1201204201209203208/Gone-to-Her-Grave-Rogue-River-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/4205200205/Burned-by-Her-Devotion-Rogue-Vows-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/1201204201209204200/Walking-on-Her-Grave-Rogue-River-4-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/9200208202/A-Bone-to-Pick-Widow-s-Island-2-by-Melinda-Leigh.pdf
    • http://xiixmcuin.linkpc.net/2209200208201208/KILL-KILL-KILL-by-Mike-Leon.pdf
    • http://xiixmcuin.linkpc.net/3202200200203207/Children-Who-Kill-an-examination-of-the-treatment-of-juveniles-who-kill-in-different-European-countries-by-Paul-Cavadino.pdf
    • http://xiixmcuin.linkpc.net/5201202208206209/Rich-Kill-Poor-Kill-by-Neil-Humphreys.pdf
    • http://xiixmcuin.linkpc.net/3209200208202208/Hopeful-Leigh-Literal-Leigh-Romance-Diaries-3-by-Melanie-James.pdf
    • http://xiixmcuin.linkpc.net/4200204207207208/To-Kill-or-Escape-To-Kill-2-by-Ryn-Shell.pdf
    • http://xiixmcuin.linkpc.net/2204208204204208/To-Kill-for-a-Ghost-To-Kill-1-by-Ryn-Shell.pdf
    • http://xiixmcuin.linkpc.net/6208202204/They-Can-t-Kill-Us-Until-They-Kill-Us-by-Hanif-Abdurraqib.pdf
    • http://xiixmcuin.linkpc.net/4201209201205202/All-You-Need-Is-Kill-Vol-1-All-You-Need-Is-Kill-1-by-Ryosuke-Takeuchi.pdf
    • http://xiixmcuin.linkpc.net/3201200208208202/Serious-Leigh-Literal-Leigh-Romance-Diaries-2-by-Melanie-James.pdf
    • http://xiixmcuin.linkpc.net/3202200200203207/Children-Who-Kill-an-examination-of-the-treatment-of-juveniles-who-kill-in-different-European-countries-by