Malicious PDF — malware analysis report

Static analysis result for SHA-256 fb5036129cd241e8…

MALICIOUS

PDF

19.7 KB Created: 2019-05-04 14:32:32 +01:00 Authoring application: mPDF 5.7
MD5: d0a218022b7963b047368200e85d30e4 SHA-1: cc57b64ce82b6129a73448433c8dfa212a64c7da SHA-256: fb5036129cd241e800533e6996287375627112ae4ba0501c932c8b75d626f207
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links were labeled as confirmed_benign, the sheer volume and the nature of the dominant host 'xiixmcuin.linkpc.net' suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xiixmcuin.linkpc.net/1201200204201/Like-Mother-Like-Daughter-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/5208201208208/The-Complete-Mother-Daughter-Book-Club-Collection-The-Mother-Daughter-Book-Club-Much-Ado-About-Anne-Dear-Pen-Pal-Pies-amp-Prejudice-Home-for-the-Holidays-Wish-You-Were-Eyre-The-Mother-Daughter-Book-Club-1-6-by-Heather-Vogel-Frederick.pdf
    • http://xiixmcuin.linkpc.net/3207209206202204/Don-t-Call-Me-Mother-Breaking-the-Chain-of-Mother-Daughter-Abandonment-by-Linda-Joy-Myers.pdf
    • http://xiixmcuin.linkpc.net/3205201201200/The-Mother-Daughter-Book-Club-The-Mother-Daughter-Book-Club-1-by-Heather-Vogel-Frederick.pdf
    • http://xiixmcuin.linkpc.net/1204207206204201/Who-Killed-My-Daughter-The-True-Story-of-a-Mother-s-Search-for-Her-Daughter-s-Murderer-by-Lois-Duncan.pdf
    • http://xiixmcuin.linkpc.net/9201202200208/Ain-t-Misbehaving-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/1202200208206/Hot-to-the-Touch-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/1201201208203/Single-Dad-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/6209204206208206/Yours-Mine-Ours-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/7206200209205202/The-Librarian-s-Daughter-the-Story-of-Sage-Greene-by-M-M-Gavillet.pdf
    • http://xiixmcuin.linkpc.net/8204209207201208/Un-toque-caliente-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/2208204200200201/Blame-It-on-Chocolate-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/9201209200200202/The-Billionaire-s-Handler-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/6207204202200204/Pink-Satin-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/9201203202207/Silver-and-Spice-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/1201209203205/Blame-It-On-Cupid-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/5200201204200207/Slow-Dance-Man-of-the-Month-22-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/1209207207203205/Like-Mother-Like-Daughter-by-Jane-Sigaloff.pdf
    • http://xiixmcuin.linkpc.net/6209200207201201/And-No-More-Sorrow-A-mother-her-daughter-their-war-by-Liliane-Pelzman.pdf
    • http://xiixmcuin.linkpc.net/4208206208203201/Baby-It-s-Cold-Outside-Blame-It-On-The-Blizzard-Deep-Freeze-Melting-Point-by-Jennifer-Greene.pdf
    • http://xiixmcuin.linkpc.net/12042