Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1fe49f0d1d8afdb…

MALICIOUS

PDF

20.4 KB Created: 2019-04-30 17:45:38 +01:00 Authoring application: mPDF 5.7
MD5: f50dbb55ad11d53b955e74d13bcd1202 SHA-1: 2d833c33a2ff31730f1e90c1b1a897c094f0c234 SHA-256: f1fe49f0d1d8afdb9e86347f152d7d6474f0bdb5967a51dd2688b458e6aca769
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm or SEO manipulation technique. While the document body is heavily obfuscated, the presence of numerous URLs suggests a potential distribution or redirection mechanism. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/8204206208205200/Chronicling-the-West-for-Harper-s-Coast-to-Coast-with-Frenzeny-Tavernier-in-1873-1874-by-Claudine-Chalmers.pdf
    • http://xiixmcuin.linkpc.net/1200207206209208206/East-Coast-West-Coast-and-Beyond-Colin-Campbell-Cooper-American-Impressionist-by-William-H-Gerdts.pdf
    • http://xiixmcuin.linkpc.net/2201209208200204/Coast-to-Coast-Paranormal-Investigation-The-Journey-Underneath-by-Carolyn-Bennett.pdf
    • http://xiixmcuin.linkpc.net/4208209206200201/Roadfood-The-Coast-to-Coast-Guide-to-800-of-the-Best-Barbecue-Joints-Lobster-Shacks-Ice-Cream-Parlors-Highway-Diners-and-Much-Much-More-by-Jane-Stern.pdf
    • http://xiixmcuin.linkpc.net/1206208209204207/The-Girls-on-the-West-Coast-by-Debbie-Lacy.pdf
    • http://xiixmcuin.linkpc.net/1207209208203205/Submitting-To-The-Boss-West-Coast-2-by-Jasmine-Haynes.pdf
    • http://xiixmcuin.linkpc.net/6209208201204/Three-Poets-Voices-from-the-West-Coast-by-Koon-Woon.pdf
    • http://xiixmcuin.linkpc.net/9207204208207204/West-Coast-Crime-Wave-by-Bill-Cameron.pdf
    • http://xiixmcuin.linkpc.net/3209206200205201/Once-a-SEAL-West-Coast-Navy-SEALs-2-by-Anne-Elizabeth.pdf
    • http://xiixmcuin.linkpc.net/4204209207207200/King-of-Snowflakes-West-Coast-Boys-1-by-Michele-Fogal.pdf
    • http://xiixmcuin.linkpc.net/1201208201208209/A-Stain-Upon-the-Sea-West-Coast-Salmon-Farming-by-Stephen-Eaton-Hume.pdf
    • http://xiixmcuin.linkpc.net/3209204208208202/A-SEAL-at-Heart-West-Coast-Navy-SEALs-1-by-Anne-Elizabeth.pdf
    • http://xiixmcuin.linkpc.net/1207205209205/Ray-Stanford-Strong-West-Coast-Landscape-Artist-by-Mark-Humpal.pdf
    • http://xiixmcuin.linkpc.net/4205206201201205/A-Century-of-Sand-Dredging-in-the-Bristol-Channel-Volume-Two-The-Welsh-Coast-Volume-Two---The-Welsh-Coast-by-Peter-Gosson.pdf
    • http://xiixmcuin.linkpc.net/1201208203201200/Clam-Gardens-Aboriginal-Mariculture-on-Canada-s-West-Coast-by-Judith-Williams.pdf
    • http://xiixmcuin.linkpc.net/2201201200208204/Two-Wheels-North-Bicycling-the-West-Coast-in-1909-by-Evelyn-McDaniel-Gibb.pdf
    • http://xiixmcuin.linkpc.net/1209209205200/Indivisible-New-Short-Fiction-By-West-Coast-Gay-and-Lesbian-Writers-by-Terry-Wolverton.pdf
    • http://xiixmcuin.linkpc.net/1203200203202202/Sailing-Back-in-Time-A-Nostalgic-Voyage-on-Canada-s-West-Coast-by-Maria-Coffey.pdf
    • http://xiixmcuin.linkpc.net/6202204208203208/The-AADA-Road-Atlas-and-Survival-Guide-The-West-Coast-Volume-2-Supplement-for-Gurps-Autoduel-and-Car-Wars-by-W-Peter-Miller.pdf
    • http://xiixmcuin.linkpc.net/5202200200204209/Coast-by-Marius-Kociejowski.pdf