Malicious PDF — malware analysis report

Static analysis result for SHA-256 eba28c4c51d0e947…

MALICIOUS

PDF

17.3 KB Created: 2019-05-02 01:38:00 +01:00 Authoring application: mPDF 5.7
MD5: 9ebd56ffcde84758373fec3e2753e122 SHA-1: 250b2717870dac178d7447bb1ad4b278b2cb1aa7 SHA-256: eba28c4c51d0e947cc4d1fa57a0169b74b7438b5e627341e9a1a0bb43d298eed
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by a critical heuristic for containing a mass external link farm, with the primary URL being http://xiixmcuin.linkpc.net/3209207203204207/Tractatus-Theologico-Politicus-by-Baruch-Spinoza.pdf. An ML classifier also strongly indicated maliciousness. The document body contains numerous embedded URLs, all pointing to the same domain and appearing to be book titles, suggesting a potential SEO poisoning or content distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/3209207203204207/Tractatus-Theologico-Politicus-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/9206209207205202/Theologisch-politische-Abhandlung-Tractatus-theologico-politicus---Vollst-ndige-deutsche-Ausgabe-Kritik-an-der-religi-sen-Intoleranz-und-ein-Pl-doyer-Gesellschaftsordnung-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/7207203207203209/The-Essential-Spinoza-Ethics-and-Related-Writings-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/1201208205207201207/Spinoza-Theologisch-politische-Abhandlung-Kritik-an-der-religi-sen-Intoleranz-und-ein-Pl-doyer-f-r-eine-s-kularisierte-Gesellschaftsordnung-by-Baruch-de-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/7207203207208202/Spinoza-s-Short-Treatise-on-God-Man-and-His-Well-Being-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/7207203207203201/Philosophy-of-Benedict-de-Spinoza-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/7207203207208206/The-Letters-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/7207203206206207/On-the-Improvement-of-the-Understanding-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/2202202201200206/Complete-Works-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/7207203207204203/Ethics-On-the-Improvement-of-the-Understanding-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/5203208209205201/L-thique-Nouvelle-dition-augment-e---Arvensa-Editions-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/7207203206206204/The-Ethics-Treatise-on-the-Emendation-of-the-Intellect-Selected-Letters-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/1200202203203207204/Samtliche-Werke-Band-2-Ethik-in-geometrischer-Ordnung-dargestellt-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/1200206200206200203/Ethik-Grossdruck-In-Geometrischer-Weise-Behandelt-in-Funf-Teilen-by-Baruch-Spinoza.pdf
    • http://xiixmcuin.linkpc.net/1201203202204200206/Tractatus-Logico-Philosophicus-by-Ludwig-Wittgenstein.pdf
    • http://xiixmcuin.linkpc.net/2204201207206202/The-Stigmatist-by-Hurd-Baruch.pdf
    • http://xiixmcuin.linkpc.net/1202205205207205/Makar-and-Baruch-Fueled-By-Lust-7-by-Celeste-Prater.pdf
    • http://xiixmcuin.linkpc.net/9202206202201208/Psychological-And-Behavioral-Aspects-Of-Diving-by-Baruch-Nevo.pdf
    • http://xiixmcuin.linkpc.net/7207203208202200/The-Trials-of-Spinoza-by-Tariq-Ali.pdf
    • http://xiixmcuin.linkpc.net/7207203207203204/Spinoza-by-Richard-H-Popkin.pdf
    • http://xiixmcuin.linkpc.net/7207203207203201/Philosophy-of-Benedict-de