Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c8c32bbbb9c311d…

MALICIOUS

PDF

20.7 KB Created: 2019-04-30 04:23:44 +01:00 Authoring application: mPDF 5.7
MD5: 09f540dbe054595c797b35c446331818 SHA-1: 3175e806f21b04038af20576fd1c639493c8ff3b SHA-256: 3c8c32bbbb9c311d5a74f2a3897ecfea014cc7bf477011f06a0693dca38ee53f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier as malicious. It contains a large number of embedded external links, a technique often used for SEO manipulation or to distribute malicious content. While the specific intent of the links is unclear, the sheer volume and the ML classification suggest a malicious purpose. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/34e74e84e54e94e5/Many-Roads-to-Travel-TJ-amp-Mare-2-by-Karen-King.pdf
    • http://unieoooq.linkpc.net/44e84e54e54e44e4/Shank-s-Mare-Japan-s-Great-Comic-Novel-of-Travel-amp-Ribaldry-by-Jippensha-Ikku.pdf
    • http://unieoooq.linkpc.net/94e94e64e14e44e5/The-Time-Travel-Trailer-Time-Travel-Trailer-1-by-Karen-Musser-Nortman.pdf
    • http://unieoooq.linkpc.net/64e84e64e44e84e7/Malaysia-Travel-Guide-The-Essential-Starter-Malaysia-Travel-Guide-Travel-Tips-On-Where-To-Go-What-To-Experience-And-How-To-Enjoy-Your-Travel-In-Malaysia-Travel-Guides-Malaysia-Travel-Tips-by-Carmen-Alia.pdf
    • http://unieoooq.linkpc.net/44e34e84e44e14e0/Bonjour-40-A-Paris-travel-log-40-years-40-days-40-seconds-by-Karen-A-Chase.pdf
    • http://unieoooq.linkpc.net/34e34e84e04e44e8/Tall-Travel-Tales-Japan-Tokyo-Takayama-and-Beyond-by-Karen-Jennings.pdf
    • http://unieoooq.linkpc.net/54e84e44e64e6/Lara-and-the-Gray-Mare-Hoofbeats-Lara-and-the-Gray-Mare-1-by-Kathleen-Duey.pdf
    • http://unieoooq.linkpc.net/34e24e44e04e24e6/What-Is-Gnosticism-by-Karen-L-King.pdf
    • http://unieoooq.linkpc.net/94e54e14e84e9/Our-Wife-amp-Other-Stories-by-Karen-King-Aribisala.pdf
    • http://unieoooq.linkpc.net/94e44e74e34e1/The-Hangman-s-Game-by-Karen-King-Aribisala.pdf
    • http://unieoooq.linkpc.net/84e94e94e54e94e9/Defending-a-King-His-Life-amp-Legacy-by-Karen-Moriarty.pdf
    • http://unieoooq.linkpc.net/34e24e34e04e14e8/Baby-Can-Travel-London---A-Travel-Guide-Made-For-Parents-by-Celine-Brewer.pdf
    • http://unieoooq.linkpc.net/64e04e34e84e64e7/The-Djibouti-Travel-Journal-by-Younghusband-World-Travel-Journals.pdf
    • http://unieoooq.linkpc.net/44e24e74e74e34e3/Pop-Travel-Pop-Travel-1-by-Tara-Tyler.pdf
    • http://unieoooq.linkpc.net/34e84e34e14e44e1/Time-Travel-in-Einstein-s-Universe-The-Physical-Possibilities-of-Travel-Through-Time-by-J-Richard-Gott-III.pdf
    • http://unieoooq.linkpc.net/74e24e24e44e74e8/Travel-Like-a-Local---Map-of-Lausanne-The-Most-Essential-Lausanne-Switzerland-Travel-Map-for-Every-Adventure-by-Maxwell-Fox.pdf
    • http://unieoooq.linkpc.net/14e94e84e64e44e7/Love-and-Travel-5-True-Love-Stories-of-My-Travel-by-German-Muhlenberg.pdf
    • http://unieoooq.linkpc.net/64e74e54e14e34e0/Phuket-The-Phuket-Travel-Guide-for-things-to-see-and-do-on-Phuket-phuket-phuket-travel-guide-phuket-island-phuket-top-10-phuket-travel-phuket-thailand-by-Abraham-Blundell.pdf
    • http://unieoooq.linkpc.net/14e04e94e04e74e94e6/From-Man-to-Mare-Time-to-Tell-by-The-Psychopath.pdf
    • http://unieoooq.linkpc.net/24e04e74e3/The-Mare-by-Mary-Gaitskill.pdf
    • http://unieoooq.linkpc.net/54e84e44e64e6/Lara-and-the-Gray-Mare-Hoofbeats-Lara-and-the-Gray-Mare-1-by-Kath