Malicious PDF — malware analysis report

Static analysis result for SHA-256 416fa7f975abcbaa…

MALICIOUS

PDF

19.6 KB Created: 2019-05-02 01:35:04 +01:00 Authoring application: mPDF 5.7
MD5: fcc75d54bd48ab6702527089cd6d9796 SHA-1: bdd3a1f1ae86f00885d17b11ef8e8d6fc21e0be7 SHA-256: 416fa7f975abcbaab0a0d2e9e90c28e9f4a88e88c56fb81a90a3087ef0cd25d2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of numerous external links. While no scripts were extracted, the sheer volume of links suggests a potential for phishing or malware distribution, aiming to direct users to malicious content hosted on these external domains. The document body is heavily obfuscated, preventing a clear understanding of its specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/74e54e84e34e04e7/Le-Ceramiche-Islamiche-Della-Collezione-Laura-The-Islamic-Ceramics-Of-The-Laura-Collection-by-Manuele-Scagliola.pdf
    • http://unieoooq.linkpc.net/84e04e94e24e94e3/The-Midnight-Diary-of-Zoya-Blume-Laura-Geringer-Books-by-Laura-Shaine-Cunningham.pdf
    • http://unieoooq.linkpc.net/94e44e54e04e34e9/Laura-will-zum-Ballett-Laura-1-by-Dagmar-Ho-feld.pdf
    • http://unieoooq.linkpc.net/74e54e84e34e64e9/La-Mafia-Restituisce-Il-Maltolto-Guida-All-applicazione-Della-Legge-109-96-Sull-uso-Sociale-Dei-Beni-Confiscati-AI-Mafiosi-by-Manuele-Braghero.pdf
    • http://unieoooq.linkpc.net/24e04e44e94e74e5/Beautiful-Angiola-The-Lost-Sicilian-Folk-and-Fairy-Tales-of-Laura-Gonzenbach-by-Laura-Gonzenbach.pdf
    • http://unieoooq.linkpc.net/54e94e14e54e84e6/Masterpieces-from-the-Gianni-Mattioli-Collection-by-Laura-Mattioli-Rossi.pdf
    • http://unieoooq.linkpc.net/34e24e24e24e3/The-Little-House-Collection-Little-House-1-9-by-Laura-Ingalls-Wilder.pdf
    • http://unieoooq.linkpc.net/34e74e24e24e14e2/The-Middlefield-Family-Collection-Treasuring-Emma-Faithful-to-Laura-Letters-to-Katie-A-Middlefield-Family-Novel-by-Kathleen-Fuller.pdf
    • http://unieoooq.linkpc.net/14e04e54e34e14e74e7/Joan-of-Arc-The-Collection-5-Collected-Works-by-Mark-Twain-Laura-E-Richards-Lord-Ronald-Gower-Lucy-Foster-Madison-and-Mrs-Oliphant-by-Mark-Twain.pdf
    • http://unieoooq.linkpc.net/74e34e04e94e4/Laura-Ingalls-Wilder-s-Fairy-Poems-by-Laura-Ingalls-Wilder.pdf
    • http://unieoooq.linkpc.net/44e24e34e34e94e7/Commit-To-Get-Fit-with-Laura-Dion-Jones-Casey-by-Laura-Dion-Jones-Casey.pdf
    • http://unieoooq.linkpc.net/34e34e24e0/Please-Don-t-Tell-by-Laura-Tims.pdf
    • http://unieoooq.linkpc.net/14e64e84e54e2/I-d-Know-You-Anywhere-by-Laura-Lippman.pdf
    • http://unieoooq.linkpc.net/14e94e54e34e14e7/Run-Away-by-Laura-Salters.pdf
    • http://unieoooq.linkpc.net/64e84e54e04e14e0/Hot-Sur-by-Laura-Restrepo.pdf
    • http://unieoooq.linkpc.net/14e94e54e94e74e0/Keep-Kept-2-by-Laura-Bailey.pdf
    • http://unieoooq.linkpc.net/34e24e64e84e74e0/Not-Yet-Not-Yet-1-by-Laura-Ward.pdf
    • http://unieoooq.linkpc.net/14e74e54e44e04e0/Initiate-by-Laura-L-Fox.pdf
    • http://unieoooq.linkpc.net/34e54e14e94e54e0/I-d-Know-You-Anywhere-by-Laura-Lippman.pdf
    • http://unieoooq.linkpc.net/24e64e84e24e5/After-I-m-Gone-by-Laura-Lippman.pdf
    • http://unieoooq.linkpc.net/24e04e44e94e74e5/Beautiful-Angiola-The-Lost-Sicilia