Malicious PDF — malware analysis report

Static analysis result for SHA-256 290a7399b4543f5b…

MALICIOUS

PDF

26.2 KB Created: 2019-05-02 01:34:53 +01:00 Authoring application: mPDF 5.7
MD5: 949a6f33a6bbd4901fd0e363155dd90a SHA-1: 58a89f37da5153c848cee045aa1d6b26553bddee SHA-256: 290a7399b4543f5bdc6d290d0f5de410758449aec897a0c79ad45e6a320e212f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, many of which are hosted on the dynamic DNS domain 'unieoooq.linkpc.net'. This behavior is indicative of a link farm or a method to distribute further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/64e94e84e94e84e9/A-Treasury-of-Chassidic-Tales-On-the-Torah----Volume-Two-by-Shlomo-Yosef-Zevin.pdf
    • http://unieoooq.linkpc.net/64e94e84e84e24e7/A-Treasury-of-Chassidic-Tales-on-the-Festivals-A-Collection-of-Inspirational-Chassidic-Stories-Relevant-to-the-Festivals-Sipure-Hasidim-Al-Ha-Moadim-by-Shlomo-Yosef-Zevin.pdf
    • http://unieoooq.linkpc.net/84e54e14e64e34e0/Articles-on-Israeli-Novelists-Including-Shmuel-Yosef-Agnon-Amos-Oz-Shlomo-Kalo-Yehuda-Amichai-RAM-Oren-Aharon-Appelfeld-Gila-Almagor-A-B-Yehoshua-David-Grossman-Meir-Shalev-Yael-Dayan-Suki-Lahav-Emile-Habibi-Amnon-Jackont-by-Hephaestus-Books.pdf
    • http://unieoooq.linkpc.net/84e04e34e44e24e1/Pentateuch-with-Targum-Onkelos-and-Rashi-s-Commentary-Torah---The-Book-of-Vayyiqra-Leviticus-Volume-III-by-Abraham-M-Silbermann.pdf
    • http://unieoooq.linkpc.net/84e04e34e44e24e0/Pentateuch-with-Targum-Onkelos-and-Rashi-s-Commentary-Torah---The-Book-of-Shemot-Exodus-Volume-II-by-Abraham-M-Silbermann.pdf
    • http://unieoooq.linkpc.net/64e44e84e74e34e9/-Mi-golah-li-geM--ulah-From-Exile-to-Redemption-Volume-1-Chassidic-teachings-of-the-Lubavitcher-Rebbe-Rabbi-Menachem-M-Schneerson-and-the-preceding-Rebbeim-of-Chab-ad-on-the-future-redemption-and-the-coming-of-Mashiach-by-Eliyahu-Friedman.pdf
    • http://unieoooq.linkpc.net/14e04e34e64e84e94e6/My-Treasury-Of-Animal-Tales-by-Anton-Kolnberger.pdf
    • http://unieoooq.linkpc.net/44e04e74e74e34e9/Ghosts-A-Treasury-of-Chilling-Tales-Old-amp-New-by-Marvin-Kaye.pdf
    • http://unieoooq.linkpc.net/24e04e44e44e64e7/The-Oxford-Treasury-of-Fairy-Tales-by-Geraldine-McCaughrean.pdf
    • http://unieoooq.linkpc.net/24e54e54e64e94e9/A-Civil-War-Treasury-of-Tales-Legends-and-Folklore-by-B-A-Botkin.pdf
    • http://unieoooq.linkpc.net/54e04e24e64e04e0/Christmas-in-My-Heart-A-Second-Treasury-More-Heartwarming-Tales-of-Holiday-Joy-by-Joe-L-Wheeler.pdf
    • http://unieoooq.linkpc.net/24e94e04e14e04e3/The-Land-of-Stories-A-Treasury-of-Classic-Fairy-Tales-by-Chris-Colfer.pdf
    • http://unieoooq.linkpc.net/34e84e84e74e24e7/A-Treasury-of-Great-Mysteries-Volume-2-by-Howard-Haycraft.pdf
    • http://unieoooq.linkpc.net/44e54e34e54e84e7/A-Treasury-of-Titanic-Tales-Stories-of-Life-and-Death-from-a-Night-to-Remember-by-Webb-Garrison.pdf
    • http://unieoooq.linkpc.net/64e94e94e34e74e4/The-Teachings-Of-Rabbi-Shlomo-Carlebach-by-Shlomo-Carlebach.pdf
    • http://unieoooq.linkpc.net/34e84e44e94e34e9/A-Treasury-of-African-American-Christmas-Stories-Volume-II-by-Bettye-Collier-Thomas.pdf
    • http://unieoooq.linkpc.net/64e94e84e74e44e7/Gabrielle-Zevin-eBook-Sampler-by-Gabrielle-Zevin.pdf
    • http://unieoooq.linkpc.net/14e44e04e74e94e0/McSweeney-s-Mammoth-Treasury-of-Thrilling-Tales-McSweeney-s-10-by-Michael-Chabon.pdf
    • http://unieoooq.linkpc.net/94e14e94e74e7/The-Torah-Codes-by-Ezra-Barany.pdf
    • http://unieoooq.linkpc.net/24e34e04e14e04e1/Mary-Engelbreit-s-Nursery-Tales-A-Treasury-of-Children-s-Classics-by-Mary-Engelbreit.pdf
    • http://unieoooq.linkpc.net/84e04e34e44e24e1/Pentateuch-with-Targum-Onkelos-and-Rashi-s-Commentary-Torah--