Malicious PDF — malware analysis report

Static analysis result for SHA-256 2993d487c6063474…

MALICIOUS

PDF

23.2 KB Created: 2019-05-02 19:34:43 +01:00 Authoring application: mPDF 5.7
MD5: ea3aac90eddadf0d0ceae44ee974fba2 SHA-1: f0786b3d3863a77991200048aac77b8db87a1571 SHA-256: 2993d487c60634748b1c183361cfcfd93cc4125c8a6e44d1ef1366830290664f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. These URLs are likely intended to lure users to malicious websites or download further malware. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/54e84e14e54e34e4/The-Battle-of-the-Somme-A-Topographical-History-by-Gerald-Gliddon.pdf
    • http://unieoooq.linkpc.net/54e84e14e54e44e5/Somme-1916-Success-and-Failure-on-the-First-Day-of-the-Battle-of-the-Somme-by-Paul-Kendall.pdf
    • http://unieoooq.linkpc.net/84e74e64e94e74e7/The-History-of-the-Russo-Japanese-War-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-Battle-of-the-Japan-Sea-Peace-Treaty-by-Sydney-Tyler.pdf
    • http://unieoooq.linkpc.net/54e84e14e54e34e2/The-Battle-of-the-Somme-The-First-and-Second-Phase-by-John-Buchan.pdf
    • http://unieoooq.linkpc.net/24e44e34e14e6/The-Great-War-July-1-1916-The-First-Day-of-the-Battle-of-the-Somme-by-Joe-Sacco.pdf
    • http://unieoooq.linkpc.net/44e84e74e64e8/The-Face-Of-Battle-A-Study-Of-Agincourt-Waterloo-And-The-Somme-by-John-Keegan.pdf
    • http://unieoooq.linkpc.net/24e54e14e24e74e9/The-Face-of-Battle-A-Study-of-Agincourt-Waterloo-and-the-Somme-by-John-Keegan.pdf
    • http://unieoooq.linkpc.net/64e64e94e84e74e1/Battles-Involving-Hanover-Battle-of-Waterloo-Battle-of-Dettingen-Battle-of-Fontenoy-Battle-of-Tourcoing-Battle-of-Melle-by-Source-Wikipedia.pdf
    • http://unieoooq.linkpc.net/84e74e64e94e84e0/The-Russo-Japanese-War-Illustrated-Edition-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-of-the-Japan-Sea-Peace-Treaty-by-Sydney-Tyler.pdf
    • http://unieoooq.linkpc.net/14e14e24e14e44e5/A-History-of-Books-by-Gerald-Murnane.pdf
    • http://unieoooq.linkpc.net/64e34e54e04e84e8/A-History-of-the-Devil-by-Gerald-Messadi-.pdf
    • http://unieoooq.linkpc.net/14e04e04e34e94e2/The-Canadian-Prairies-A-History-by-Gerald-Friesen.pdf
    • http://unieoooq.linkpc.net/34e94e64e74e84e9/The-History-and-Topography-of-Ireland-by-Gerald-of-Wales.pdf
    • http://unieoooq.linkpc.net/44e04e24e34e54e7/Writing-To-Heal-by-Lee-Gliddon.pdf
    • http://unieoooq.linkpc.net/44e04e34e54e64e6/God-s-Bankers-A-History-of-Money-and-Power-at-the-Vatican-by-Gerald-Posner.pdf
    • http://unieoooq.linkpc.net/54e04e84e44e04e8/Karl-Marx-s-Theory-of-History-A-Defence-by-Gerald-A-Cohen.pdf
    • http://unieoooq.linkpc.net/24e64e84e84e04e9/The-Battle-A-New-History-of-Waterloo-by-Alessandro-Barbero.pdf
    • http://unieoooq.linkpc.net/14e14e74e14e94e84e4/Battle-Angel-Alita-Barjack-Battle-Angel-Battle-Angel-Alita-Chapters-Battle-Angel-Alita-Characters-Battle-Angel-Alita-Images-by-Source-Wikia.pdf
    • http://unieoooq.linkpc.net/74e44e84e64e14e4/The-Battle-of-Britain-Five-Months-That-Changed-History-May-October-1940-by-James-Holland.pdf
    • http://unieoooq.linkpc.net/24e54e64e74e54e4/The-Hinges-of-Battle-How-Change-and-Incompetence-Have-Changed-the-Face-of-History-by-Erik-Durschmied.pdf
    • http://unieoooq.linkpc.net/24e44e34e14e6/The-Great-War-July-1-1916-The-First-Day-of-the-Battle-of-the-Somme-by-