Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b75681c65b1d787…

MALICIOUS

PDF

22.7 KB Created: 2019-04-30 19:42:11 +01:00 Authoring application: mPDF 5.7
MD5: aae5933bec30cf97ed73d6e93b19a685 SHA-1: f1f0e434549102d3f12a3efda0797b1b921f515c SHA-256: 4b75681c65b1d7873c9a6d3cfa8d952f668f5406ff68dd794385331e3f25775f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by an ML classifier as malicious. A critical heuristic identified a large number of embedded external links, suggesting a link farm or distribution mechanism. While most extracted URLs were labeled as benign, the sheer volume and the heuristic firing indicate a suspicious pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/84e14e24e64e54e3/Francis-Picabia-Classique-Et-Merveilleux-by-Francis-Picabia.pdf
    • http://unieoooq.linkpc.net/84e14e24e64e44e8/I-Am-a-Beautiful-Monster-Selected-Writings-of-Francis-Picabia-by-Francis-Picabia.pdf
    • http://unieoooq.linkpc.net/84e14e24e64e04e6/Yes-No-Poems-and-Sayings-Hanuman-Book-39-by-Francis-Picabia.pdf
    • http://unieoooq.linkpc.net/84e14e24e54e94e7/Duchamp-Man-Ray-Picabia-by-Jennifer-Mundy.pdf
    • http://unieoooq.linkpc.net/84e14e24e64e44e4/Modern-Antiquity-Picasso-de-Chirico-L-ger-Picabia-by-Christopher-Green.pdf
    • http://unieoooq.linkpc.net/74e54e64e34e04e5/Ring-Noir-Quand-Appollinaire-Cendrars-Et-Picabia-Decouvraient-Les-Boxeurs-Negres-by-Claude-Meunier.pdf
    • http://unieoooq.linkpc.net/84e44e94e74e54e4/The-Essays-or-Counsels-Civil-and-Moral-of-Francis-Ld-Verulam-Viscount-St-Albans-by-Francis-Bacon.pdf
    • http://unieoooq.linkpc.net/84e64e34e54e9/Dick-Francis-s-Bloodline-by-Felix-Francis.pdf
    • http://unieoooq.linkpc.net/74e04e94e84e24e7/A-Communicant-Instructed-Or-Practical-Directions-for-Worthy-Receiving-of-the-Lords-Supper-by-Francis-Roberts-1676-by-Francis-Roberts.pdf
    • http://unieoooq.linkpc.net/64e94e64e14e7/The-Francis-A-Schaeffer-Trilogy-The-3-Essential-Books-in-1-Volume-the-God-Who-Is-There-Escape-from-Reason-He-Is-There-and-He-Is-Not-Silent-by-Francis-A-Schaeffer.pdf
    • http://unieoooq.linkpc.net/34e64e14e54e54e3/The-Complete-Works-of-Francis-A-Schaeffer-A-Christian-Worldview-5-Volume-Set-by-Francis-A-Schaeffer.pdf
    • http://unieoooq.linkpc.net/84e64e04e44e64e2/A-Moral-Enterprise-Essays-in-Honor-of-Francis-Canavan-by-Francis-Canavan.pdf
    • http://unieoooq.linkpc.net/54e84e24e44e34e8/Fantastic-Flagg-Two-Tales-of-Early-Science-Fiction-from-Francis-Flagg-by-Francis-Flagg.pdf
    • http://unieoooq.linkpc.net/14e14e84e94e94e04e8/Flappers-and-Philosophers-1920-by-Francis-Scott-Fitzgerald-Francis-Scott-Key-Fitzgerald-September-24-1896---December-21-1940-Known-Professionally-as-F-Scott-Fitzgerald-Was-an-American-Novelist-and-Short-Story-Writer-Whose-Works-Illustrate-by-F-Scott-Fitzgerald.pdf
    • http://unieoooq.linkpc.net/54e54e94e94e04e3/The-Little-Flowers-of-St-Francis-of-Assisi-by-Francis-of-Assisi.pdf
    • http://unieoooq.linkpc.net/84e14e24e54e44e1/Incognito-by-Francis-Ray.pdf
    • http://unieoooq.linkpc.net/14e14e84e54e04e1/Primed-by-G-P-Francis.pdf
    • http://unieoooq.linkpc.net/84e14e14e44e3/The-God-Who-Is-There-by-Francis-A-Schaeffer.pdf
    • http://unieoooq.linkpc.net/64e14e84e94e14e7/Fragile-by-Eve-Francis.pdf
    • http://unieoooq.linkpc.net/54e94e24e84e44e1/Somebody-s-Knocking-at-My-Door-by-Francis-Ray.pdf
    • http://unieoooq.linkpc.net/84e44e94e74e54e4/The-Essays-or-Counsel