Malicious PDF — malware analysis report

Static analysis result for SHA-256 582df66312df9562…

MALICIOUS

PDF

20.0 KB Created: 2019-05-04 13:27:07 +01:00 Authoring application: mPDF 5.7
MD5: 392dbfc0e2182388955e91665e46e08b SHA-1: ae81f4a88477c5eba91d0a5c77b74f7301e01426 SHA-256: 582df66312df95626031a760649ec6478c39b3044f2282b0d1c80a959c035727
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear to point to benign book titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/74e54e94e64e04e8/Adam-s-Return-The-Five-Promises-of-Male-Initiation-by-Richard-Rohr.pdf
    • http://unieoooq.linkpc.net/14e44e34e44e54e3/Simplicity-The-Freedom-of-Letting-Go-by-Richard-Rohr.pdf
    • http://unieoooq.linkpc.net/74e44e94e54e74e0/A-Lever-and-a-Place-to-Stand-The-Contemplative-Stance-the-Active-Prayer-by-Richard-Rohr.pdf
    • http://unieoooq.linkpc.net/14e04e44e64e94e54e4/The-RETURN-of-the-INKA-A-Journey-of-Initiation-amp-Inka-Prophecies-for-2012-by-Elizabeth-B-Jenkins.pdf
    • http://unieoooq.linkpc.net/34e44e04e04e94e2/Star-Wars-Infinities---Return-of-the-Jedi-by-Adam-Gallardo.pdf
    • http://unieoooq.linkpc.net/74e54e94e64e04e0/The-Initiation-by-Paul-J-Sneddon-by-The-Initiation.pdf
    • http://unieoooq.linkpc.net/24e94e54e64e94e5/Threesomes-Male-Female-Male-by-Darren-G-Burton.pdf
    • http://unieoooq.linkpc.net/14e14e44e34e64e34e2/Promises-Promises-Princess-Luanne-and-Wizard-Heatheria-by-Charles-A-Johnson.pdf
    • http://unieoooq.linkpc.net/64e24e94e94e0/God-s-Promises-For-You-Divine-Promises-and-Affirmations-For-Your-Success-All-round-Prosperity-and-Total-Well-being-by-Theo-John-Paul.pdf
    • http://unieoooq.linkpc.net/64e54e44e74e84e0/Return-to-the-Fatherland-by-Richard-Paraiso.pdf
    • http://unieoooq.linkpc.net/54e94e14e94e14e9/Kickboxing-The-Cross-Hook-And-Uppercut-From-Initiation-To-Knockout-Everything-You-Need-To-Know-and-more-To-Master-The-Pain-Game-Kickboxing-From-Initiation-To-Knockout-by-Martina-Sprague.pdf
    • http://unieoooq.linkpc.net/14e24e04e74e64e6/The-Coming-Return-of-the-Yahweh-by-Richard-Vadim.pdf
    • http://unieoooq.linkpc.net/74e24e14e14e6/Promises-Linger-Promises-1-by-Sarah-McCarty.pdf
    • http://unieoooq.linkpc.net/24e54e74e54e94e7/Male-Seeking-Male-by-Kathleen-Lee.pdf
    • http://unieoooq.linkpc.net/64e54e64e84e34e4/Male-Male-by-Seth-King.pdf
    • http://unieoooq.linkpc.net/24e54e14e64e5/I-Remember-Lemuria-And-The-Return-Of-Sathanas-Forgotten-Books-by-Richard-S-Shaver.pdf
    • http://unieoooq.linkpc.net/14e94e24e34e64e2/Making-Promises-Promises-2-by-Amy-Lane.pdf
    • http://unieoooq.linkpc.net/84e24e14e04e74e1/The-Power-of-Return-Return-to-Me-That-I-May-Return-to-You-Zech-1-3-by-John-Goyette.pdf
    • http://unieoooq.linkpc.net/44e94e04e44e94e9/American-Pharaoh-Mayor-Richard-J-Daley---His-Battle-for-Chicago-and-the-Nation-by-Adam-Cohen.pdf
    • http://unieoooq.linkpc.net/24e94e44e14e74e6/A-is-for-Alpha-Male-A-is-for-Alpha-Male-1-by-Laurel-Ulen-Curtis.pdf
    • http://unieoooq.linkpc.net/64e24e94e94e0/God-s-Promi