Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ad7c16db30d0495…

MALICIOUS

PDF

20.1 KB Created: 2019-04-30 03:43:08 +01:00 Authoring application: mPDF 5.7
MD5: 25e9bc044f74d45d2aac1c8fef4e1eec SHA-1: e80b69adffa9af137af4b09842e51ae3ab72cd65 SHA-256: 5ad7c16db30d0495b29ebbedf1af0987c41443aac4139888fe66ceebe99d15c2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. These links point to various PDF documents hosted on the 'unieoooq.linkpc.net' domain. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be a link farm designed to direct users to potentially harmful content or facilitate SEO manipulation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e04e04e14e54e8/The-Many-Landfalls-of-John-Cabot-by-Peter-E-Pope.pdf
    • http://unieoooq.linkpc.net/34e24e54e44e74e0/Pope-Patrick-by-Peter-de-Rosa.pdf
    • http://unieoooq.linkpc.net/14e14e64e14e04e64e4/The-Princess-Diaries-Seventh-Heaven-by-Cabot-Meg-7-edition-2007-by-Meg-Cabot.pdf
    • http://unieoooq.linkpc.net/84e44e34e04e34e2/The-Pope-and-the-Freemasons-The-Letter-quot-Humanum-Genus-quot-of-the-Pope-Leo-XIII-Against-Free-Masonry-and-the-Spirit-of-the-Age-by-Pope-Leo-XIII.pdf
    • http://unieoooq.linkpc.net/14e44e24e74e64e9/The-Lonely-Cold-War-of-Pope-Pius-XII-The-Roman-Catholic-Church-and-the-Division-of-Europe-1943-1950-by-Peter-C-Kent.pdf
    • http://unieoooq.linkpc.net/44e24e34e54e84e7/In-God-s-Name-An-Investigation-into-the-Murder-of-Pope-John-Paul-I-by-David-A-Yallop.pdf
    • http://unieoooq.linkpc.net/14e14e34e84e24e94e9/All-the-Pope-s-Saints-The-Jesuits-Who-Shaped-Pope-Francis-by-Sean-Salai-S.pdf
    • http://unieoooq.linkpc.net/94e74e24e14e94e5/The-Pope-amp-the-CEO-John-Paul-II-s-Leadership-Lessons-to-a-Young-Swiss-Guard-by-Andreas-Widmer.pdf
    • http://unieoooq.linkpc.net/74e24e14e94e14e3/Pope-John-Paul-IIs-Theological-Journey-to-the-Prayer-Meeting-of-Religions-in-Assisi-Part-2-3-by-Johannes-D-rmann.pdf
    • http://unieoooq.linkpc.net/74e34e94e44e24e6/A-Present-for-a-Papist-Or-the-History-of-the-Life-of-Pope-Joan-Taken-Mainly-from-A-Cooke-s-Pope-Joane-by-Alexander-Cooke.pdf
    • http://unieoooq.linkpc.net/74e34e94e44e24e9/A-Present-for-a-Papist-Or-the-History-of-the-Life-of-Pope-Joan-taken-Mainly-from-A-Cooke-s-Pope-Joane-by-Alexander-Cooke.pdf
    • http://unieoooq.linkpc.net/14e24e44e24e14e2/Phoebe-Pope-and-the-Year-of-Four-Phoebe-Pope-Novel-1-by-Nya-Jade.pdf
    • http://unieoooq.linkpc.net/14e74e24e44e24e2/Dead-Medium-by-Peter-John.pdf
    • http://unieoooq.linkpc.net/44e14e94e54e74e6/Peter-s-Chair-by-John-Simpson.pdf
    • http://unieoooq.linkpc.net/14e64e54e34e5/John-le-Carr-by-Peter-Lewis.pdf
    • http://unieoooq.linkpc.net/24e64e74e64e74e1/Dead-Medium-by-Peter-John.pdf
    • http://unieoooq.linkpc.net/44e94e44e04e44e3/Peter-and-Alice-by-John-Logan.pdf
    • http://unieoooq.linkpc.net/24e44e14e34e34e8/Rosa-Luxemburg-by-John-Peter-Nettl.pdf
    • http://unieoooq.linkpc.net/64e34e14e84e94e2/Il-faut-tuer-Peter-Pan-by-John-Verdon.pdf
    • http://unieoooq.linkpc.net/44e24e34e74e2/Black-Maps-John-March-1-by-Peter-Spiegelman.pdf