Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f75f826fabfd7c1…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 17:47:02 +01:00 Authoring application: mPDF 5.7
MD5: 4f9d1d32856ce490279fcaddb716234d SHA-1: 986d13167e52d48172108c95f9bd8bfd1b4b49f4 SHA-256: 1f75f826fabfd7c142cc5f1499b31eafd5c5e63f26f3239836c4eadd7d8c956f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While the extracted URLs are currently marked as benign, the sheer volume and nature of the links suggest a malicious intent to distribute or obscure malicious destinations.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/74e74e04e24e94e7/Life-in-Five-Seconds-by-Matteo-Civaschi.pdf
    • http://unieoooq.linkpc.net/14e04e34e24e94e74e8/Gefl-gelte-Worte-in-5-Sekunden-by-Matteo-Civaschi.pdf
    • http://unieoooq.linkpc.net/14e14e34e64e84e94e6/Articles-on-Films-Shot-in-Hungary-Including-Hudson-Hawk-Spy-Game-Citizen-X-Underworld-2003-Film-the-Golden-Compass-Film-Eragon-Film-Hum-DIL-de-Chuke-Sanam-Munich-Film-Robin-Hood-2006-TV-Series-by-Hephaestus-Books.pdf
    • http://unieoooq.linkpc.net/34e24e74e94e44e1/Novelle-Di-Matteo-Bandello-by-Matteo-Bandello.pdf
    • http://unieoooq.linkpc.net/84e24e74e14e7/Film-Form-Essays-In-Film-Theory-by-Sergei-Eisenstein.pdf
    • http://unieoooq.linkpc.net/54e24e54e14e44e2/Film-Letton-Le-Bal-Des-Lucioles-Midsummer-Madness-Film-2007-Lotte-from-Gadgetville-Les-Trois-Mousquetaires-by-Livres-Groupe.pdf
    • http://unieoooq.linkpc.net/14e14e94e14e64e64e2/Film-Technique-and-Film-Acting-by-Vsevolod-Pudovkin.pdf
    • http://unieoooq.linkpc.net/14e14e74e64e44e64e5/Thirty-Seconds-to-Die-Thirty-Seconds-to-Die-1-by-S-G-Holster.pdf
    • http://unieoooq.linkpc.net/14e04e64e54e44e2/Thirty-Seconds-to-Die-Thirty-Seconds-to-Die-1-by-S-G-Holster.pdf
    • http://unieoooq.linkpc.net/74e74e04e34e84e0/Matteo-by-Guenter-Tolar.pdf
    • http://unieoooq.linkpc.net/94e94e94e94e54e7/Batman-Europa-2-by-Matteo-Casali.pdf
    • http://unieoooq.linkpc.net/84e54e14e94e54e5/Denti-guasti-by-De-Simone-Matteo.pdf
    • http://unieoooq.linkpc.net/14e04e04e34e64e1/The-Last-Anglo-Indians-by-Sonina-Matteo.pdf
    • http://unieoooq.linkpc.net/54e04e14e44e54e9/World-Unfurled-by-Matteo-Pericoli.pdf
    • http://unieoooq.linkpc.net/74e74e04e34e84e6/The-City-Out-My-Window-63-Views-on-New-York-by-Matteo-Pericoli.pdf
    • http://unieoooq.linkpc.net/44e24e74e34e74e6/The-House-of-the-Scorpion-Matteo-Alacran-1-by-Nancy-Farmer.pdf
    • http://unieoooq.linkpc.net/14e04e94e84e04e34e7/Film-in-Danemark-Danischer-Film-Filmfestival-in-Danemark-Filmgesellschaft-Danemark-Filmpreis-Danemark-Kira-Olsenbande-Antichr-by-Quelle-Wikipedia.pdf
    • http://unieoooq.linkpc.net/64e84e44e04e04e9/The-Aftermath-of-Syllogism-Aristotelian-Logical-Argument-from-Avicenna-to-Hegel-by-Matteo-Cosci.pdf
    • http://unieoooq.linkpc.net/74e74e04e34e94e2/Mission-to-China-Matteo-Ricci-and-the-Jesuit-Encounter-with-the-East-by-Mary-Laven.pdf
    • http://unieoooq.linkpc.net/24e44e94e94e04e0/Seconds-by-Bryan-Lee-O-39-Malley.pdf