Malicious PDF — malware analysis report

Static analysis result for SHA-256 412deb99833fb6ca…

MALICIOUS

PDF

21.2 KB Created: 2019-05-03 05:59:04 +01:00 Authoring application: mPDF 5.7
MD5: a633e602a71e1a0f494e7368a1d9e11c SHA-1: 21a910043792e1e334ae94093ad335590f67e43e SHA-256: 412deb99833fb6caa38417ef3b279eaa04d60c64110fc86548becadd4cfc3d35
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of external links, forming a link farm. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a collection of PDFs hosted on the `unieoooq.linkpc.net` domain, likely as a lure or to distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/84e14e64e54e94e2/A-Lenda-Do-Vale-Dormir-The-Legend-of-Sleepy-Hollow-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/44e54e34e54e94e9/The-Legend-of-Sleepy-Hollow-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/24e44e04e54e24e4/The-Legend-of-Sleepy-Hollow-and-Other-Stories-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/14e14e84e44e24e14e2/The-Legend-of-Sleepy-Hollow-amp-Other-Tales-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/44e44e44e94e54e6/The-Legend-of-Sleepy-Hollow-and-Other-Tales-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/74e94e94e94e54e2/The-Legend-of-Sleepy-Hollow-and-Other-Macabre-Tales-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/14e14e54e14e04e14e3/The-legend-of-Sleepy-Hollow-Found-Among-the-Papers-of-the-Late-Diedrich-Knickerbocker-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/84e04e94e04e44e6/The-Legend-of-Sleepy-Hollow-English-German-edition-illustrated-Die-Sage-von-der-schl-frigen-Schlucht-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/94e24e24e04e54e8/The-Legend-of-Sleepy-Hollow-and-Other-Stories-1000-Copy-Limited-Edition-Or-the-Sketch-Book-of-Geoffrey-Crayon-Gent-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/94e24e84e24e54e9/Die-Legende-von-Sleepy-Hollow-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/34e24e74e64e74e3/Sleepy-Hollow-and-Other-Short-Stories-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/94e04e34e04e84e7/The-Legend-of-Sleepy-Hollow-by-Gris-Grimly.pdf
    • http://unieoooq.linkpc.net/84e54e84e04e84e8/The-Legend-of-Sleepy-Hollow-by-Timothy-Baril.pdf
    • http://unieoooq.linkpc.net/44e24e64e64e64e3/The-Headless-Horseman-A-Retelling-of-the-Legend-of-Sleepy-Hollow-by-Emma-Harding.pdf
    • http://unieoooq.linkpc.net/24e34e74e04e64e6/Sleepy-Hollow-Vol-1-Sleepy-Hollow-Comics-1-by-Marguerite-Bennett.pdf
    • http://unieoooq.linkpc.net/84e74e94e04e54e5/Murder-amp-Mystery-The-Hound-of-the-Baskervilles-Macbeth-The-Legend-of-Sleepy-Hollow-by-Monica-Rausch.pdf
    • http://unieoooq.linkpc.net/74e24e24e84e84e8/Tales-of-Terror-Dracula-Frankenstein-The-Legend-of-Sleepy-Hollow-The-Phantom-of-the-Opera-and-13-More-Works-of-Vampires-Ghosts-and-Classic-Horror-by-Bram-Stoker.pdf
    • http://unieoooq.linkpc.net/84e54e14e54e14e0/The-Sketch-Book-by-Washington-Irving-with-Sketch-of-the-Author-s-Life-and-Compositional-Critical-and-Explanatory-Notes-By-G-A-Chase-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/34e24e44e94e84e2/Old-Christmas-From-the-Sketch-Book-of-Washington-Irving-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/44e14e14e54e04e4/The-Complete-Tales-of-Washington-Irving-by-Washington-Irving.pdf
    • http://unieoooq.linkpc.net/84e04e94e04e44e6/The-Legend-of-Sleepy-Hollow-English-German-edition-illustrated-Die-Sage-von-der