Malicious PDF — malware analysis report

Static analysis result for SHA-256 582e44151d86e55e…

MALICIOUS

PDF

15.9 KB Created: 2019-05-02 02:44:40 +01:00 Authoring application: mPDF 5.7
MD5: c5cbbadaa2ddfe15bca2aa23b93b7328 SHA-1: 22173e282a2a01f42c3dd3514970b7fef145c268 SHA-256: 582e44151d86e55eecf2d67b04eccde76abc9ef43990b338a08fb14be5451703
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a heuristic firing for a large number of external links, suggesting a link farm or a method to distribute malicious content. While the URLs themselves are currently marked as benign, the sheer volume and the ML classifier's high confidence indicate a malicious intent. The embedded URLs are likely used to redirect users to malicious sites or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/24e74e04e44e24e5/Searching-for-Jesus-New-Discoveries-in-the-Quest-for-Jesus-of-Nazareth-and-How-They-Confirm-the-Gospel-Accounts-by-Robert-J-Hutchinson.pdf
    • http://unieoooq.linkpc.net/34e74e24e44e24e7/Claudius-the-God-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/44e94e34e64e14e8/Diamond-Eye-by-Robert-C-J-Graves.pdf
    • http://unieoooq.linkpc.net/34e94e14e14e14e9/Goodbye-to-All-That-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/14e04e24e54e04e54e0/Lawrence-and-the-Arabs-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/34e04e34e24e04e0/Hercules-My-Shipmate-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/84e34e44e64e5/The-Greek-Myths-Vol-2-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/44e94e34e64e14e7/Nightmarism-Poems-by-Robert-C-J-Graves.pdf
    • http://unieoooq.linkpc.net/14e94e34e14e34e9/Good-Bye-to-All-That-An-Autobiography-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/84e34e74e54e3/Homer-s-Daughter-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/54e04e14e54e44e3/Sergeant-Lamb-s-America-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/44e04e14e84e14e3/Claudius-the-God-and-His-Wife-Messalina-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/14e84e74e14e54e4/Poems-Selected-by-Himself-Fourth-Edition-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/34e14e34e04e74e7/The-Crowning-Privilege-Collected-Essays-on-Poetry-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/24e94e84e14e84e3/The-Greek-Myths-The-Complete-and-Definitive-Edition-by-Robert-Graves.pdf
    • http://unieoooq.linkpc.net/44e24e34e14e64e9/Words-of-Jesus-Bible-King-James-Version-by-Russell-Sherrard.pdf
    • http://unieoooq.linkpc.net/24e54e24e44e24e8/King-s-Cross-The-Story-of-the-World-in-the-Life-of-Jesus-by-Timothy-J-Keller.pdf
    • http://unieoooq.linkpc.net/14e04e34e54e74e1/Honest-to-Jesus-by-Robert-W-Funk.pdf
    • http://unieoooq.linkpc.net/74e24e04e04e14e1/A-Different-Jesus-The-Christ-of-the-Latter-day-Saints-by-Robert-L-Millet.pdf
    • http://unieoooq.linkpc.net/34e64e34e24e5/Jesus-Freaks-Stories-of-Those-Who-Stood-for-Jesus-the-Ultimate-Jesus-Freaks-Jesus-Freaks-1-by-D-C-Talk.pdf
    • http://unieoooq.linkpc.net/44e04e