Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8acb36869a21e0f…

MALICIOUS

PDF

16.4 KB Created: 2019-05-02 01:38:19 +01:00 Authoring application: mPDF 5.7
MD5: ce900a751063be5513782f4cb1d6f717 SHA-1: b5f606f185c3cd93ad22eb6b1e88285e9668e13c SHA-256: e8acb36869a21e0ff63509004aa5208c1e4e0e1d3ecba41af6fa955b73efdce2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to other PDF files, identified as a link farm. While the specific content of the linked PDFs is benign, the technique of embedding numerous links suggests an attempt to manipulate search engine results or distribute content through a link farm. The ML classifier also flagged this PDF as malicious, increasing the confidence in its suspicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.n
    • http://xiixmcuin.linkpc.net/1200202207205204/Debbie-Macomber-s-Cedar-Cove-Series-First-Six-Books-by-Debbie-Macomber.pdf
    • http://xiixmcuin.linkpc.net/9202204204203/I-Don-t-Have-to-Make-Everything-All-Better-by-Gary-B-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/2203200201205205/Bo-Bo-and-Cha-Cha-s-Big-Day-Out-by-Jason-Erik-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200201204/LONTAR-2-by-Jason-Erik-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200205200/The-Rockefeller-Syndrome-by-Ferdinand-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207203207200207/Cracks-in-the-Constitution-by-Ferdinand-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200204202/Politicians-and-Other-Scoundrels-by-Ferdinand-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200204205/Severed-Trust-by-George-D-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/5205204207204203/Knit-Along-with-Debbie-Macomber-Twenty-Wishes-by-Debbie-Macomber.pdf
    • http://xiixmcuin.linkpc.net/5202200205205209/A-Curious-Bundle-for-Bo-Bo-and-Cha-Cha-by-Jason-Erik-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200201200/Swedish-Christmas-Crafts-by-Helene-S-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207204200204209/Kla-Judrikis-No-Ohsolakalna-Pee-Deewaatsihschanas-Nahze-by-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207203207200206/Fish-Eats-Lion-by-Jason-Erik-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207203205203200/Anisett-Lundberg-California-1851-by-Kathleen-Duey.pdf
    • http://xiixmcuin.linkpc.net/8207203209203208/Medieval-Inspired-Knits-Stunning-Brocade-amp-Swirling-Vine-Patterns-with-Embellished-Borders-by-Anna-Karin-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/8207203207200209/The-Book-of-Shiatsu-A-Complete-Guide-to-Using-Hand-Pressure-and-Gentle-Manipulation-to-Improve-Your-Health-Vitality-and-Stamina-by-Paul-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/1206209200202208/The-Rich-and-the-Super-Rich-A-Study-in-the-Power-of-Money-Today-by-Ferdinand-Lundberg.pdf
    • http://xiixmcuin.linkpc.net/7201204204202200/My-New-Big-Kid-Bed-by-Debbie-Bertram.pdf
    • http://xiixmcuin.linkpc.net/1206208207201207/No-Shade-is-Better-Than-the-Other-by-Debbie-Lacy.pdf
    • http://xiixmcuin.linkpc.net/6202204205/Any-Dream-Will-Do-by-Debbie-Macomber.pdf