Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d45165b9eeb30c7…

MALICIOUS

PDF

21.5 KB Created: 2019-05-02 01:24:27 +01:00 Authoring application: mPDF 5.7
MD5: a05e1056076ee543fa6ded0478865561 SHA-1: 0a5b6c946440b8c2f24112e67a5bfdb0dd22a586 SHA-256: 2d45165b9eeb30c799ba191e4e9fd68c5f33bd9f40180308d4efd3cd3ddb13e4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body text is heavily corrupted, the presence of numerous links suggests a tactic to redirect users to potentially malicious websites. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/24e14e84e94e14e8/The-Children-of-Tamal-The-Shaytonian-Chronicles-3-by-Karen-Fainges.pdf
    • http://unieoooq.linkpc.net/24e64e24e24e04e2/Where-Children-Run-by-Karen-Emilson.pdf
    • http://unieoooq.linkpc.net/24e34e64e14e64e2/The-Ivy-Chronicles-by-Karen-Quinn.pdf
    • http://unieoooq.linkpc.net/34e94e34e74e14e1/The-Chronicles-of-Marr-nia-by-Karen-Cantwell.pdf
    • http://unieoooq.linkpc.net/24e84e74e34e44e1/Sky-Children-Lacuna-Chronicles-2-by-A-M-Daily.pdf
    • http://unieoooq.linkpc.net/14e44e04e64e24e0/First-Dance-The-Bridesmaid-Chronicles-3-by-Karen-Kendall.pdf
    • http://unieoooq.linkpc.net/54e04e24e94e3/The-Chronicles-of-Articia-Children-of-the-Dead-by-K-D-Enos.pdf
    • http://unieoooq.linkpc.net/44e34e04e64e14e4/Angel-of-Death-The-Chosen-Chronicles-1-by-Karen-Dales.pdf
    • http://unieoooq.linkpc.net/44e94e24e24e44e0/Angel-of-Death-The-Chosen-Chronicles-1-by-Karen-Dales.pdf
    • http://unieoooq.linkpc.net/44e94e94e44e24e7/Beyond-the-Ashes-Golden-Gate-Chronicles-2-by-Karen-Barnett.pdf
    • http://unieoooq.linkpc.net/34e54e34e44e04e1/Gather-the-Children-Chronicles-of-the-Maca-2-by-Mari-Collier.pdf
    • http://unieoooq.linkpc.net/14e14e44e04e04e54e0/The-Children-of-The-Resistance-The-Mir-Chronicles-Book-2-by-Leisa-Wallace.pdf
    • http://unieoooq.linkpc.net/14e14e24e84e94e54e0/Zettai-Karen-Children-THE-UNLIMITED-Hyoubu-Kyousuke-THE-UNLIMITED-1-by-Takashi-Shiina.pdf
    • http://unieoooq.linkpc.net/14e14e24e84e94e54e1/Zettai-Karen-Children-THE-UNLIMITED-Hyoubu-Kyousuke-THE-UNLIMITED-2-by-Takashi-Shiina.pdf
    • http://unieoooq.linkpc.net/84e44e84e44e04e7/Valkyria---Games-Valkyria-Chronicles-Valkyria-Chronicles-2-Valkyria-Chronicles-3-Valkyria-Chronicles-Valkyria-Chronicles-2-Valkyria-Chronicles-3-Action-Points-Challenges-of-the-Edy-Detachment-Class-Change-System-Col-Nonnenkof-by-Source-Wikia.pdf
    • http://unieoooq.linkpc.net/14e04e44e74e14e5/Children-of-the-Lion-Cheysuli-Omnibus-3-Chronicles-of-the-Cheysuli-5-6-by-Jennifer-Roberson.pdf
    • http://unieoooq.linkpc.net/14e94e24e04e04e7/Children-of-Dune-Dune-Chronicles-3-by-Frank-Herbert.pdf
    • http://unieoooq.linkpc.net/24e54e04e34e5/Children-of-Dune-Dune-Chronicles-3-by-Frank-Herbert.pdf
    • http://unieoooq.linkpc.net/84e74e54e34e64e2/The-Way-to-Write-for-Children-An-Introduction-to-the-Craft-of-Writing-Children-s-Literature-by-Joan-Aiken.pdf
    • http://unieoooq.linkpc.net/14e04e74e94e04e94e5/Heidi-with-Fifty-Pictures-and-Illustrations-For-children-and-those-who-love-children-by-Johanna-Spyri.pdf
    • http://unieoooq.linkpc.net/44e94e94e44e24e7/Beyond-the-Ashes-Golden-Gate-Chronicles-2-by-Kare