Malicious PDF — malware analysis report

Static analysis result for SHA-256 f103a3f297f1a538…

MALICIOUS

PDF

17.8 KB Created: 2019-05-05 16:09:07 +01:00 Authoring application: mPDF 5.7
MD5: 342329f6f2d15d5059a9f8c431ae5d79 SHA-1: fa04a4b23fc07206038525ebc7d9a73301bbc761 SHA-256: f103a3f297f1a538c31c10feb8b8b09996c0da4711462c5166a45987d6d9daf0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, hosted on the domain xiixmcuin.linkpc.net. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4201209207206206/The-Penguin-Anthology-of-Australian-Women-s-Writing-by-Dale-Spender.pdf
    • http://xiixmcuin.linkpc.net/4208201208206205/P-I-Penguin-and-the-Case-of-the-Christmas-Lights-P-I-Penguin-Specials-Book-1-by-Bec-J-Smith.pdf
    • http://xiixmcuin.linkpc.net/1208206204208209/Coo-ee-Tales-of-Australian-Life-by-Australian-Ladies-by-Harriet-Anne-Patchett-Martin.pdf
    • http://xiixmcuin.linkpc.net/1201208202205201203/Medicine-of-Australian-Mammals-An-Australian-Perspective-by-Woods-Rupert-Vogelnest-Larry.pdf
    • http://xiixmcuin.linkpc.net/1209204202208206/The-Penguin-Book-of-First-World-War-Poetry-by-Jon-Silkin.pdf
    • http://xiixmcuin.linkpc.net/4203207204200200/Amazonian-Penguin-Book-of-New-Womens-Tra-by-Dea-Birkett.pdf
    • http://xiixmcuin.linkpc.net/4201204201202204/The-Penguin-Book-of-the-Sonnet-by-Phillis-Levin.pdf
    • http://xiixmcuin.linkpc.net/7203201209201203/Harry-Potter-and-the-Prisoner-of-Azkaban-Harry-Potter-3-Picture-Book-by-J-K-Rowling.pdf
    • http://xiixmcuin.linkpc.net/1206206208208203/Recitation-of-the-Noble-Qur-an-with-verse-by-verse-English-Translation-of-its-Meanings-by-Anonymous.pdf
    • http://xiixmcuin.linkpc.net/2201208209204205/The-Penguin-Book-of-Vampire-Stories-by-Alan-Ryan.pdf
    • http://xiixmcuin.linkpc.net/4205208202203208/The-Penguin-Book-of-First-World-War-Poetry-by-George-Walter.pdf
    • http://xiixmcuin.linkpc.net/3205202207202202/The-Penguin-Book-of-Caribbean-Short-Stories-by-E-A-Markham.pdf
    • http://xiixmcuin.linkpc.net/4201204201203200/The-Penguin-Book-of-Irish-Fiction-by-Colm-T-ib-n.pdf
    • http://xiixmcuin.linkpc.net/3202205203207207/The-New-Penguin-Book-of-Scottish-Short-Stories-by-Ian-Murray.pdf
    • http://xiixmcuin.linkpc.net/2206209202201201/Harry-and-Lola-go-camping-The-Adventures-Harry-amp-Lola-One-Naughty-Brat-amp-Her-Step-Dad-Book-2-A-Forbidden-Taboo-Story-by-Lola-Popsicle.pdf
    • http://xiixmcuin.linkpc.net/3202207206207209/The-Second-Penguin-Book-of-English-Short-Stories-by-Christopher-Dolley.pdf
    • http://xiixmcuin.linkpc.net/3202207206206204/The-New-Penguin-Book-of-Welsh-Short-Stories-by-Alun-Richards.pdf
    • http://xiixmcuin.linkpc.net/4205208209204200/The-Penguin-Book-of-Modern-African-Poetry-by-Gerald-Moore.pdf
    • http://xiixmcuin.linkpc.net/1201200202204201200/The-Oxford-Book-of-Children-s-Verse-by-Iona-Opie.pdf
    • http://xiixmcuin.linkpc.net/7204201202207/The-Penguin-Book-Birds-In-Suits-2006-Publication-by-Mark-Norman.pdf
    • http://xiixmcuin.linkpc.net/1206206208208203/Recitation-of-the-Noble-Qur-an-with-verse-by-verse