Malicious PDF — malware analysis report

Static analysis result for SHA-256 2044425f64eb706c…

MALICIOUS

PDF

15.3 KB Created: 2019-04-30 05:29:36 +01:00 Authoring application: mPDF 5.7
MD5: 0cd187eb1a7f87fe653ddba6c557f90e SHA-1: 412615357ddff55887cd14028fc7d6d20d363523 SHA-256: 2044425f64eb706cd17359666604ad5b7d4c416f102576694feaf9fc55859cd3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic. The majority of these links point to external PDF files hosted on the same domain, suggesting a coordinated effort to distribute content or manipulate search engine results. While the document body is unreadable, the heuristic and the sheer volume of links indicate a malicious intent, likely to lure users to malicious sites or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/24e04e44e34e74e8/The-Highlander-s-Princess-Bride-The-Improper-Princesses-3-by-Vanessa-Kelly.pdf
    • http://unieoooq.linkpc.net/34e44e94e04e54e8/My-Fair-Princess-The-Improper-Princesses-1-by-Vanessa-Kelly.pdf
    • http://unieoooq.linkpc.net/24e54e24e24e04e5/His-Mistletoe-Bride-The-Stanton-Family-4-by-Vanessa-Kelly.pdf
    • http://unieoooq.linkpc.net/34e44e94e14e74e6/The-Improper-Bride-Sisters-of-Scandal-5-by-Lily-Maxton.pdf
    • http://unieoooq.linkpc.net/14e44e94e64e44e6/Jahanara-Princess-of-Princesses-by-Kathryn-Lasky.pdf
    • http://unieoooq.linkpc.net/14e24e04e54e0/The-Barefoot-Princess-Lost-Princesses-2-by-Christina-Dodd.pdf
    • http://unieoooq.linkpc.net/14e94e94e64e24e4/Princess-of-Glass-The-Princesses-of-Westfalin-2-by-Jessica-Day-George.pdf
    • http://unieoooq.linkpc.net/34e54e74e14e2/Princess-of-Glass-The-Princesses-of-Westfalin-Trilogy-2-by-Jessica-Day-George.pdf
    • http://unieoooq.linkpc.net/34e94e44e34e44e4/How-to-Lose-a-Bride-in-One-Night-Forgotten-Princesses-3-by-Sophie-Jordan.pdf
    • http://unieoooq.linkpc.net/24e94e34e34e94e1/Rock-n-Roll-Princesses-Wear-Black-by-Kelly-Polark.pdf
    • http://unieoooq.linkpc.net/44e34e14e54e64e8/Princess-of-the-Midnight-Ball-The-Princesses-of-Westfalin-Trilogy-1-by-Jessica-Day-George.pdf
    • http://unieoooq.linkpc.net/34e84e04e04e2/Princess-of-the-Silver-Woods-The-Princesses-of-Westfalin-Trilogy-3-by-Jessica-Day-George.pdf
    • http://unieoooq.linkpc.net/14e24e14e04e44e5/Princess-of-the-Silver-Woods-The-Princesses-of-Westfalin-Trilogy-3-by-Jessica-Day-George.pdf
    • http://unieoooq.linkpc.net/34e04e04e54e34e4/Improper-Lessons-Improper-1-by-Dawn-Ryder.pdf
    • http://unieoooq.linkpc.net/24e04e44e64e14e5/Three-Renegades-and-a-Baby-by-Vanessa-Kelly.pdf
    • http://unieoooq.linkpc.net/34e64e84e64e84e5/Their-Captivated-Bride-Bridgewater-Menage-3-by-Vanessa-Vale.pdf
    • http://unieoooq.linkpc.net/44e84e04e14e84e8/The-Butterfly-Bride-Advertisements-for-Love-3-by-Vanessa-Riley.pdf
    • http://unieoooq.linkpc.net/34e64e84e74e04e7/Their-Christmas-Bride-Bridgewater-Menage-5-by-Vanessa-Vale.pdf
    • http://unieoooq.linkpc.net/44e94e74e04e64e6/The-Highlander-s-Sin-Stolen-Bride-6-by-Eliza-Knight.pdf
    • http://unieoooq.linkpc.net/14e74e34e94e54e5/How-to-Plan-a-Wedding-for-a-Royal-Spy-The-Renegade-Royals-3-by-Vanessa-Kelly.pdf
    • http://unieoooq.linkpc.net/44