Malicious PDF — malware analysis report

Static analysis result for SHA-256 04fca9da0fd96aa4…

MALICIOUS

PDF

20.1 KB Created: 2019-05-02 01:13:39 +01:00 Authoring application: mPDF 5.7
MD5: 4103327185e286e5a4930bac9ff67df7 SHA-1: f2c07f50cae052561a693e248973d0e2f5489253 SHA-256: 04fca9da0fd96aa4bee352b518e147800d6e601513bcb99be03eda2e6f7015d5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, pointing to various e-book PDFs. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent to drive traffic or potentially distribute further payloads. No scripts were extracted, but the PDF structure itself is indicative of a link-distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/84e64e24e14e34e6/Romeo-und-Julia-Romeo-and-Juliet-Zweisprachig-Englisch-Deutsch-ebook-Seite-f-r-Seite-Bilingual-English-German-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/14e14e84e44e74e94e2/Der-Schimmelreiter-The-Rider-on-the-White-Horse---Bilingual-German-English-Edition-zweisprachig-Deutsch-Englisch-by-Theodor-Storm.pdf
    • http://unieoooq.linkpc.net/14e04e64e54e64e84e7/Romeo-and-Juliet---Romeo-und-Julia-von-William-Shakespeare-K-nigs-Erl-uterungen-Textanalyse-und-Interpretation-mit-ausf-hrlicher-Inhaltsangabe-und-Abituraufgaben-mit-L-sungen-by-Tamara-Kutscher.pdf
    • http://unieoooq.linkpc.net/54e34e14e24e54e8/Romeo-And-Juliet-Original-Text-And-Facing-Pages-Translation-Into-Contemporary-English-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/54e34e14e24e14e4/Romeo-and-Juliet-German-Learning-Edition-with-Paragraph-By-Paragraph-Translation-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/64e04e94e74e74e8/Romeo-and-Juliet-Original-Text-of-Masuccio-Salernitano-Luigi-Da-Porto-Matteo-Bandello-William-Shakespeare-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/84e24e74e04e14e7/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/74e74e14e34e24e6/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/74e24e14e44e34e3/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/94e44e74e34e44e7/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/84e24e14e84e14e7/Romeo-And-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/54e44e24e34e94e6/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/84e94e54e04e34e6/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/44e24e84e64e74e9/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/54e54e94e84e54e5/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/54e44e24e94e04e4/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/34e44e84e74e44e9/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/74e74e64e54e34e9/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/64e94e84e34e64e9/Romeo-and-Juliet-by-William-Shakespeare.pdf
    • http://unieoooq.linkpc.net/94e84e64e04e94e5/Romeo-and-Juliet-by-William-Shakespeare.pdf