Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a24ef512c0c808b…

MALICIOUS

PDF

18.1 KB Created: 2019-05-01 18:32:32 +01:00 Authoring application: mPDF 5.7
MD5: 8e7019f6b645ce2eca9682146ddbb754 SHA-1: ccc6f00909bca9f75465ff6720cc2006320a0c9e SHA-256: 0a24ef512c0c808b1a5cb268c26d2703dd8da91a3051d168a5137235b59fd7e2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files hosted on a dynamic DNS domain. This heuristic firing, combined with the ML classifier, strongly suggests a malicious intent to redirect users to potentially harmful content, likely for SEO poisoning or to host malicious documents. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/24e84e14e64e94e1/Bait-by-Tiffinie-Helmer.pdf
    • http://unieoooq.linkpc.net/34e14e94e24e54e0/Hooked-Romance-on-the-Edge-2-by-Tiffinie-Helmer.pdf
    • http://unieoooq.linkpc.net/24e14e94e94e94e5/Edge-Romance-on-the-Edge-1-by-Tiffinie-Helmer.pdf
    • http://unieoooq.linkpc.net/24e84e04e04e64e3/The-St-Valentine-s-Day-Massacre-The-Untold-Story-of-the-Gangland-Bloodbath-That-Brought-Down-Al-Capone-by-William-J-Helmer.pdf
    • http://unieoooq.linkpc.net/94e44e64e54e84e4/Wild-Men-of-Alaska-Wild-Men-of-Alaska-1-4-by-Tiffinie-Helmer.pdf
    • http://unieoooq.linkpc.net/24e74e34e54e24e3/Miss-Lonelyhearts-Bloody-Valentine-1-by-Eva-Natsumi.pdf
    • http://unieoooq.linkpc.net/14e04e64e34e4/Medium-Raw-A-Bloody-Valentine-to-the-World-of-Food-and-the-People-Who-Cook-by-Anthony-Bourdain.pdf
    • http://unieoooq.linkpc.net/14e14e14e34e34e64e0/Bloody-Freak-A-Bloody-1-by-Emily-Barker.pdf
    • http://unieoooq.linkpc.net/94e24e64e24e94e8/Best-Valentine-s-Day-Comeplete-Guide-For-a-Perfect-Valentine-s-Day-by-Duby-Nevo.pdf
    • http://unieoooq.linkpc.net/24e84e54e34e24e8/Bloody-Jack-Being-an-Account-of-the-Curious-Adventures-of-Mary-quot-Jacky-quot-Faber-Ship-s-Boy-Bloody-Jack-1-by-L-A-Meyer.pdf
    • http://unieoooq.linkpc.net/24e44e44e74e24e4/Bloody-Jack-Being-an-Account-of-the-Curious-Adventures-of-Mary-quot-Jacky-quot-Faber-Ship-s-Boy-Bloody-Jack-1-by-L-A-Meyer.pdf
    • http://unieoooq.linkpc.net/14e04e74e04e34e4/Vegan-Virgin-Valentine-V-Valentine-1-by-Carolyn-Mackler.pdf
    • http://unieoooq.linkpc.net/94e44e94e34e14e1/Sharing-Snowy-by-Marilyn-Helmer.pdf
    • http://unieoooq.linkpc.net/84e14e24e84e34e1/Faith-of-Qumran-Theology-of-the-Dead-Sea-Scrolls-by-Helmer-Ringgren.pdf
    • http://unieoooq.linkpc.net/54e04e44e04e94e6/Lord-Valentine-s-Castle-Majipoor-Lord-Valentine-1-by-Robert-Silverberg.pdf
    • http://unieoooq.linkpc.net/44e34e64e64e9/Dante-Valentine-The-Complete-Series-Dante-Valentine-1-5-by-Lilith-Saintcrow.pdf
    • http://unieoooq.linkpc.net/44e74e64e64e04e5/The-Cowboy-of-Valentine-Valley-Valentine-Valley-3-by-Emma-Cane.pdf
    • http://unieoooq.linkpc.net/14e94e24e04e04e6/Bloody-Ground-by-John-F-Day.pdf
    • http://unieoooq.linkpc.net/64e14e74e44e34e7/Bloody-Signorina-by-Joseph-D-39-Agnese.pdf
    • http://unieoooq.linkpc.net/24e54e84e44e64e4/Best-Served-Bloody-by-Sinead-MacDughlas.pdf