Malicious PDF — malware analysis report

Static analysis result for SHA-256 57e9f7a665440f18…

MALICIOUS

PDF

18.9 KB Created: 2019-04-30 05:42:23 +01:00 Authoring application: mPDF 5.7
MD5: 5be47d8ab154c3ef6228d69f614452ab SHA-1: 22dc3adeb882556951ee185c5834aa4c281b7e43 SHA-256: 57e9f7a665440f1850d8db15259ec219895ff5ccdb75f96cde90bbd76337f181
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates this is a technique to distribute malicious content or to engage in SEO manipulation. While the specific URLs extracted were classified as benign, the sheer volume and structure suggest a malicious intent to redirect users to potentially harmful content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e04e44e34e24e1/The-Faith-What-Christians-Believe-Why-They-Believe-It-and-Why-It-Matters-by-Charles-W-Colson.pdf
    • http://unieoooq.linkpc.net/94e44e34e84e3/Born-Again-by-Charles-W-Colson.pdf
    • http://unieoooq.linkpc.net/24e74e14e24e94e7/How-Now-Shall-We-Live-by-Charles-W-Colson.pdf
    • http://unieoooq.linkpc.net/74e54e64e64e6/Life-Sentence-by-Charles-W-Colson.pdf
    • http://unieoooq.linkpc.net/34e64e14e74e94e9/Red-Letter-Christians-A-Christian-s-Guide-to-Faith-and-Politics-a-Citizen-s-Guide-to-Faith-and-Politics-by-Tony-Campolo.pdf
    • http://unieoooq.linkpc.net/74e04e94e84e24e0/A-Manual-of-Faith-and-Life-A-Guide-for-Individual-Christians-or-Communicant-Classes-by-Hugh-T-Kerr.pdf
    • http://unieoooq.linkpc.net/24e54e04e84e44e9/What-Good-Is-God-In-Search-of-a-Faith-That-Matters-by-Philip-Yancey.pdf
    • http://unieoooq.linkpc.net/64e24e84e84e44e4/Jews-and-Christians-on-Time-and-Eternity-Charles-P-guy-s-Portrait-of-Bernard-Lazare-by-Annette-Aronowicz.pdf
    • http://unieoooq.linkpc.net/34e04e84e64e64e7/The-Sara-Colson-Trilogy-The-Sara-Colson-Trilogy-1-3-by-Susan-Elle.pdf
    • http://unieoooq.linkpc.net/34e44e54e84e04e4/Faith-and-the-Good-Thing-by-Charles-R-Johnson.pdf
    • http://unieoooq.linkpc.net/14e44e84e64e9/Charles-and-Emma-The-Darwins-Leap-of-Faith-by-Deborah-Heiligman.pdf
    • http://unieoooq.linkpc.net/74e04e54e94e44e1/Dorothea-Trudel-Or-The-Prayer-Of-Faith-1865-by-Charles-Cullis.pdf
    • http://unieoooq.linkpc.net/24e54e24e44e94e0/The-Closing-of-the-Western-Mind-The-Rise-of-Faith-and-the-Fall-of-Reason-by-Charles-Freeman.pdf
    • http://unieoooq.linkpc.net/74e04e64e34e34e1/Strangers-in-a-Strange-Land-Living-the-Catholic-Faith-in-a-Post-Christian-World-by-Charles-J-Chaput.pdf
    • http://unieoooq.linkpc.net/24e84e94e24e04e7/Zone-One-by-Colson-Whitehead.pdf
    • http://unieoooq.linkpc.net/94e14e84e54e9/Sag-Harbor-by-Colson-Whitehead.pdf
    • http://unieoooq.linkpc.net/34e54e04e04e44e8/The-Redeemers-Quinn-Colson-5-by-Ace-Atkins.pdf
    • http://unieoooq.linkpc.net/34e64e04e44e84e0/The-Redeemers-Quinn-Colson-5-by-Ace-Atkins.pdf
    • http://unieoooq.linkpc.net/34e74e74e6/The-Underground-Railroad-by-Colson-Whitehead.pdf
    • http://unieoooq.linkpc.net/44e64e24e24e74e6/The-Sinners-Quinn-Colson-8-by-Ace-Atkins.pdf
    • http://unieoooq.linkpc.net/64e24e84e84e44e4/Jews-an