Malicious PDF — malware analysis report

Static analysis result for SHA-256 2496c7ff4c4b3aae…

MALICIOUS

PDF

19.4 KB Created: 2019-05-01 20:13:28 +01:00 Authoring application: mPDF 5.7
MD5: 6edbf9dffa5dc54940280882e17e2315 SHA-1: 67801a4a2236f1d3c2f1c2419f4453427dfab8da SHA-256: 2496c7ff4c4b3aae6f806e75312e9a0737fdac3a7a0365ac200ab45b21b20182
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were labeled as confirmed benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to redirect users to potentially harmful content. The document body itself is heavily obfuscated but contains repeated instances of these URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e14e84e54e94e64e4/Collected-Plays-One-Baal-Drums-in-the-Night-In-the-Jungle-of-Cities-Life-of-Edward-II-of-England-amp-5-One-Act-Plays-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/94e14e54e74e54e6/In-the-Jungle-of-Cities-Bertolt-Brecht-Collected-Plays-Vol-1-Pt-4-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/94e14e54e84e54e3/A-Respectable-Wedding-and-Other-One-Act-Plays-Bertolt-Brecht-Collected-Plays-Vol-1-Pt-2-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/94e14e54e64e04e5/Seven-Plays-of-Bertolt-Brecht-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/74e84e84e14e24e1/Jewish-Wife-and-Other-Short-Plays-Includes-In-Search-of-Justice-Informer-Elephant-Calf-Measures-Taken-Exception-and-the-Rule-Salzburg-Dance-of-Death-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/94e14e54e74e54e8/Werkstatt-Bertolt-Brecht-The-Bertolt-Brecht-Workshop-by-Wolfgang-Gersch.pdf
    • http://unieoooq.linkpc.net/74e84e84e04e64e6/Collected-Short-Stories-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/94e14e54e74e64e1/Die-St-cke-von-Bertolt-Brecht-in-einem-Band-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/74e84e74e94e84e3/Brecht-on-Theatre-The-Development-of-an-Aesthetic-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/14e34e64e94e14e2/Collected-Plays-1944-1961-by-Arthur-Miller.pdf
    • http://unieoooq.linkpc.net/14e54e94e14e54e4/The-Zoo-Story-and-Other-Plays-by-Edward-Albee.pdf
    • http://unieoooq.linkpc.net/14e14e14e74e74e54e9/Patrick-Pearse-Collected-Plays-Dramai-an-Phiarsaigh-by-Eugene-McNulty.pdf
    • http://unieoooq.linkpc.net/94e14e44e14e64e8/Selected-Poems-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/84e54e74e64e6/The-Threepenny-Opera-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/24e64e44e84e24e5/Stories-of-Mr-Keuner-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/14e34e74e64e44e6/Fear-and-Misery-in-the-Third-Reich-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/94e14e54e84e44e4/The-Visions-of-Simone-Machard-by-Bertolt-Brecht.pdf
    • http://unieoooq.linkpc.net/24e24e24e14e44e5/Plays-5-Arcadia-The-Real-Thing-Night-and-Day-Indian-Ink-Hapgood-by-Tom-Stoppard.pdf
    • http://unieoooq.linkpc.net/94e14e54e64e84e1/Bertolt-Brecht-s-Berlin-A-Scrapbook-of-the-Twenties-by-Wolf-Von-Eckardt.pdf
    • http://unieoooq.linkpc.net/14e04e54e04e44e24e3/The-Plays-of-Anton-Chekhov-Nine-Plays-Including-the-Sea-Gull-the-Cherry-Orchard-the-Three-Sisters-and-Others-by-Anton-Chekhov.pdf
    • http://unieoooq.linkpc.net/74e84e84e14e24e1/Jewish-Wife-and-Other-Short-Plays-Includes-In-Search-of-Justice-Informer-Elephant-Calf-Measures-Taken-Exception-and-the-Rule-Sa