Malicious PDF — malware analysis report

Static analysis result for SHA-256 36013a1ea57e8e67…

MALICIOUS

PDF

28.4 KB Created: 2019-05-02 18:07:41 +01:00 Authoring application: mPDF 5.7
MD5: 57c162f8a8b5517724ec80187754ce26 SHA-1: 0249134423fed0e5a040afbf670900cabd6639f5 SHA-256: 36013a1ea57e8e67eb546a2c054b9b98be71bdefa5233d1384f53beb0c93427f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' and the sheer volume of links suggest a malicious intent to redirect users to potentially harmful content hosted on the 'linkpc.net' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.link
    • http://unieoooq.linkpc.net/24e64e14e24e74e7/No-More-Tomorrows-The-Compelling-True-Story-of-an-Innocent-Woman-Sentenced-to-Twenty-Years-in-a-Hellhole-Bali-Prison-by-Kathryn-Bonella.pdf
    • http://unieoooq.linkpc.net/94e24e64e94e84e0/Blasphemy-the-true-heartbreaking-story-of-the-woman-sentenced-to-death-over-a-cup-of-water-by-Asia-Bibi.pdf
    • http://unieoooq.linkpc.net/44e94e94e54e64e6/Is-William-Martinez-Not-Our-Brother-Twenty-Years-of-the-Prison-Creative-Arts-Project-by-Buzz-Alexander.pdf
    • http://unieoooq.linkpc.net/14e04e64e74e04e04e9/The-True-Story-of-Andersonville-Prison-A-Defense-of-Major-Henry-Wirz-The-Prisoners-and-Their-Keepers-Daily-Life-at-Prison-Execution-of-the-Raiders-the-Accusations-Against-Wirz-The-Trial-by-George-Rawlinson.pdf
    • http://unieoooq.linkpc.net/34e74e64e54e94e7/Searching-for-Tomorrow-Tomorrows-1-by-Kathryn-McNeill-Crane.pdf
    • http://unieoooq.linkpc.net/44e34e64e14e1/Searching-for-Tomorrow-Tomorrows-1-by-Kathryn-McNeill-Crane.pdf
    • http://unieoooq.linkpc.net/14e04e64e64e94e14e9/The-True-Story-of-Andersonville-Prison-A-Defense-of-Major-Henry-Wirz-by-James-Madison-Page.pdf
    • http://unieoooq.linkpc.net/84e44e64e3/Indianapolis-The-True-Story-of-the-Worst-Sea-Disaster-in-U-S-Naval-History-and-the-Fifty-Year-Fight-to-Exonerate-an-Innocent-Man-by-Lynn-Vincent.pdf
    • http://unieoooq.linkpc.net/64e44e14e64e7/Hellhole-Hellhole-1-by-Brian-Herbert.pdf
    • http://unieoooq.linkpc.net/74e34e64e24e04e0/Getting-Life-An-Innocent-Man-s-25-Year-Journey-from-Prison-to-Peace-by-Michael-Morton.pdf
    • http://unieoooq.linkpc.net/24e34e34e14e54e7/Out-of-Mormonism-A-Woman-s-True-Story-by-Judy-Robertson.pdf
    • http://unieoooq.linkpc.net/44e74e64e24e74e3/Yorkshire-Ripper---The-Secret-Murders-The-True-Story-of-How-Peter-Sutcliffe-s-Terrible-Reign-of-Terror-Claimed-at-Least-Twenty-Two-More-Lives-by-Chris-Clark.pdf
    • http://unieoooq.linkpc.net/14e04e24e14e54e04e5/Following-Daisies---A-True-Story-About-One-Woman-s-Adventures-by-Heather-J-Pardon.pdf
    • http://unieoooq.linkpc.net/14e24e74e94e64e4/I-Know-Why-We-re-Here-The-True-Story-of-an-Ordinary-Woman-s-Extraordinary-Gift-by-Mia-Dolan.pdf
    • http://unieoooq.linkpc.net/14e64e14e34e74e6/When-I-Fell-from-the-Sky-The-True-Story-of-One-Woman-s-Miraculous-Survival-by-Juliane-Koepcke.pdf
    • http://unieoooq.linkpc.net/14e84e54e44e14e7/Albatross-The-True-Story-of-a-Woman-s-Survival-at-Sea-by-Deborah-Scaling-Kiley.pdf
    • http://unieoooq.linkpc.net/34e74e34e1/Trials-of-the-Earth-The-True-Story-of-a-Pioneer-Woman-by-Mary-Mann-Hamilton.pdf
    • http://unieoooq.linkpc.net/54e34e64e84e04e0/D-ARTAGNAN-ROMANCES-The-Three-Musketeers-Twenty-Years-After-The-Vicomte-de-Bragelonne-Ten-Years-Later-Louise-de-la-Valliere-The-Man-in-the-Iron-Mask-FLT-Classics-Series-by-Alexandre-Dumas.pdf
    • http://unieoooq.linkpc.net/44e74e84e04e74e9/Sentenced-to-Life-The-Story-of-a-Survivor-of-the-Lahwah-Ghetto-by-Kopel-Kolpanitzky.pdf
    • http://unieoooq.linkpc.net/44e24e84e14e44e7/The-King-s-Mistress-The-True-and-Scandalous-Story-of-the-Woman-Who-Stole-the-Heart-of-George-I-by-Claudia-Gold.pdf