Malicious PDF — malware analysis report

Static analysis result for SHA-256 f4eb7bcf9665d7dc…

MALICIOUS

PDF

13.4 KB Created: 2019-05-02 03:43:53 +01:00 Authoring application: mPDF 5.7
MD5: c8ef1397edcc76f8b0985f822de693c5 SHA-1: 3f0e2585f60ef0a755d45ef8139340616fcdf6f7 SHA-256: f4eb7bcf9665d7dc8e4a93e851a8c368e709a739fd224eed14f946ec5b446471
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign content, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to serve as a distribution point for further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/4207204209201/The-Dive-From-Clausen-s-Pier-by-Ann-Packer.pdf
    • http://xiixmcuin.linkpc.net/8208207208207207/Fan-Pier-and-Pier-4-Transportation-Impact-and-Access-Plan-by-Vanasse-Hangen-Brustlin.pdf
    • http://xiixmcuin.linkpc.net/1201208200200204208/Crash-Dive-Crash-Dive-1-by-Craig-DiLouie.pdf
    • http://xiixmcuin.linkpc.net/3204202207202207/Reejecttion-by-Daniel-Clausen.pdf
    • http://xiixmcuin.linkpc.net/1200201209207206201/River-by-Lowen-Clausen.pdf
    • http://xiixmcuin.linkpc.net/2200200205206/The-Prosperine-Papers-by-Jan-Clausen.pdf
    • http://xiixmcuin.linkpc.net/1201209207202203204/Bubba-the-Bulldog-Tries-to-Smile-by-Bree-Clausen.pdf
    • http://xiixmcuin.linkpc.net/4205205207200204/I-Love-You-Honey-But-the-Season-s-Over-by-Connie-Clausen.pdf
    • http://xiixmcuin.linkpc.net/1200202208205205200/Sophienlust-98---Liebesroman-Einem-Fremden-berlassen-by-Bettina-Clausen.pdf
    • http://xiixmcuin.linkpc.net/4208201200207/Spiritual-Space-The-Religious-Architecture-of-Pietro-Belluschi-by-Meredith-L-Clausen.pdf
    • http://xiixmcuin.linkpc.net/5200200202202/Mendocino-And-Other-Stories-by-Ann-Packer.pdf
    • http://xiixmcuin.linkpc.net/3200209204206/The-Unwinding-by-George-Packer.pdf
    • http://xiixmcuin.linkpc.net/2207201205204208/Evangelism-and-the-Sovereignty-of-God-by-J-I-Packer.pdf
    • http://xiixmcuin.linkpc.net/1201209204208202208/Nach-all-diesen-Jahren-by-Joy-Packer.pdf
    • http://xiixmcuin.linkpc.net/4207206206203208/The-Village-of-Waiting-by-George-Packer.pdf
    • http://xiixmcuin.linkpc.net/3208204209203201/A-Christmas-Parable-by-Boyd-K-Packer.pdf
    • http://xiixmcuin.linkpc.net/9201200202208203/The-Restoration-of-Otto-Laird-by-Nigel-Packer.pdf
    • http://xiixmcuin.linkpc.net/1201203209202204205/Guide-to-George-Packer-s-the-Unwinding-by-Eureka.pdf
    • http://xiixmcuin.linkpc.net/6205206200205203/Monochrome-Painting-in-Black-and-White-by-Lelia-Packer.pdf
    • http://xiixmcuin.linkpc.net/2203204207208/The-Assassins-Gate-America-in-Iraq-by-George-Packer.pdf
    • http://xiixmcuin.linkpc.net/2207201205204208/Evangelism-and-the-Sovereignty-o