Malicious PDF — malware analysis report

Static analysis result for SHA-256 06b9ee61835a2124…

MALICIOUS

PDF

23.2 KB Created: 2019-05-02 17:11:33 +01:00 Authoring application: mPDF 5.7
MD5: 7b54e35462c316383d45c8ef01ec729c SHA-1: be2dbf5c7ca295307a94d60c864f463d00ad963f SHA-256: 06b9ee61835a212430c15f6a2bde4979746cd930f49f8fe57b77412489b739de
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on a dynamic DNS domain. This suggests a link farm or redirection scheme designed to direct users to potentially malicious content. The ML classifier also flagged this PDF as malicious, increasing confidence in its suspicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e04e04e04e24e54e1/Comus-amp-Lycida-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e24e64e5/Milton-s-Comus-Lycidas-and-Other-Poems-and-Matthew-Arnold-s-Address-on-Milton-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e54e54e0/Select-Minor-Poems-of-John-Milton-Hymn-of-the-Nativity-l-Allegro-Il-Penseroso-Comus-Lycidas-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e44e84e3/Select-Minor-Poems-of-John-Milton-Hymn-on-the-Nativity-l-Allegro-Il-Penseroso-Comus-Lycidas-Sonnets-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e44e94e7/Milton-s-Minor-Poems-L-Allegro-Il-Penseroso-Comus-and-Lycidas-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e34e64e3/Lycidas-Comus-L-Allegro-Il-Penseroso-and-Other-Poems-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e44e84e0/Milton-s-Comus-Lycidas-and-Other-Poems-And-Matthew-Arnold-s-Address-on-Milton-by-Andrew-J-George.pdf
    • http://unieoooq.linkpc.net/14e14e64e84e34e44e1/Areopagitica-A-speech-of-Mr-John-Milton-for-the-Liberty-of-Unlicenc-d-Printing-to-the-Parlament-of-England-Annotated-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e34e54e1/The-Complete-Poetical-Works-of-John-Milton-Paradise-Lost-Paradise-Regain-d-Samson-Agonistes-Psalms-Sonnets-The-Passion-on-Time-on-Shakespear-L-allegro-Il-Penseroso-Arcades-Lycidas-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e44e94e1/Milton-s-L-Allegro-Il-Penseroso-and-Lycidas-Ed-with-an-Intr-Paraphrase-and-Vocabularies-by-F-S-Aldhouse-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e34e64e0/Milton-s-Paradise-Lost-and-Lycidas-Books-I-and-II-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e24e54e8/The-Lycidas-and-Epitaphium-Damonis-of-Milton-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e14e44e94e14e34e2/Milton-s-Paradise-Lost-With-Copious-Notes-Explanatory-and-Critical-Partly-Selected-from-the-Various-Commentators-and-Partly-Original-Also-a-Memoir-of-His-Life-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e24e44e8/Lycidas-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/84e84e84e84e64e9/Paradise-Lost-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/54e24e44e44e84e1/Paradise-Lost-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e24e54e0/Lycidas-Sonnets-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/34e94e84e34e84e9/Paradise-Lost-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/84e44e44e84e74e1/Paradise-Lost-by-John-Milton.pdf
    • http://unieoooq.linkpc.net/14e04e44e84e94e54e2/Paradise-Lost-by-John-Milton.pdf