Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e4181b8cb3d057e…

MALICIOUS

PDF

19.9 KB Created: 2019-05-03 05:23:21 +01:00 Authoring application: mPDF 5.7
MD5: c25c9bc4e4b97f11d3ba4d2d9a8f4a32 SHA-1: f9fae266e69afec2a1d9263815aec696348d2e90 SHA-256: 5e4181b8cb3d057e69df003d35915f3bdbddefa4e34d09e007a837e4cbc7a639
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, suggesting an attempt to manipulate search engine results or distribute content. While the specific URLs are currently marked as benign, the sheer volume and the heuristic firing indicate a suspicious pattern. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/34e04e64e14e94e4/Angel-amp-Faith-Daddy-Issues-Part-3-Angel-amp-Faith-8-by-Christos-Gage.pdf
    • http://unieoooq.linkpc.net/34e04e54e94e94e3/Angel-amp-Faith-Family-Reunion-Part-2-Angel-amp-Faith-12-by-Christos-Gage.pdf
    • http://unieoooq.linkpc.net/24e84e74e74e44e5/Angel-amp-Faith-Live-Through-This-Part-1-Angel-amp-Faith-1-by-Christos-Gage.pdf
    • http://unieoooq.linkpc.net/24e84e84e44e74e8/Angel-amp-Faith-Live-Through-This-Part-4-Angel-amp-Faith-4-by-Christos-Gage.pdf
    • http://unieoooq.linkpc.net/24e84e14e24e94e4/Angel-amp-Faith-What-You-Want-Not-What-You-Need-Angel-amp-Faith-Volume-5-by-Christos-Gage.pdf
    • http://unieoooq.linkpc.net/44e44e34e44e44e9/Angel-amp-Faith-Season-9-Volume-3-by-Christos-Gage.pdf
    • http://unieoooq.linkpc.net/94e74e04e14e24e3/Angel-amp-Faith-Bd-3-Familientreffen-by-Chistos-Gage.pdf
    • http://unieoooq.linkpc.net/14e24e54e44e24e9/Fallen-Angel-Part-3---A-Mafia-Romance-Fallen-Angel-3-by-Tracie-Podger.pdf
    • http://unieoooq.linkpc.net/34e04e54e64e94e9/Angel-Surrogates-Chapter-1-Angel-Comic-01-Angel-Season-1-by-Christopher-Golden.pdf
    • http://unieoooq.linkpc.net/94e54e24e64e64e6/Anti-Semitism-and-Early-Christianity-Issues-of-Polemic-and-Faith-by-Craig-A-Evans.pdf
    • http://unieoooq.linkpc.net/14e14e04e34e04e1/Daddy-s-Little-Angel-Bedeviled-1-by-Shani-Petroff.pdf
    • http://unieoooq.linkpc.net/14e14e74e14e94e84e4/Battle-Angel-Alita-Barjack-Battle-Angel-Battle-Angel-Alita-Chapters-Battle-Angel-Alita-Characters-Battle-Angel-Alita-Images-by-Source-Wikia.pdf
    • http://unieoooq.linkpc.net/24e64e24e14e84e1/Siege-To-Green-Angel-Tower-Part-1-Memory-Sorrow-and-Thorn-3-Part-1-by-Tad-Williams.pdf
    • http://unieoooq.linkpc.net/34e64e94e84e14e5/The-Baptist-Faith-and-Message-2000-Critical-Issues-in-America-s-Largest-Protestant-Denomination-by-Douglas-K-Blount.pdf
    • http://unieoooq.linkpc.net/44e94e24e64e84e8/Buffy-the-Vampire-Slayer-Angel-The-Hollower-Part-1-Buffy-the-Vampire-Slayer-Angel-1-Comic-by-Joss-Whedon.pdf
    • http://unieoooq.linkpc.net/14e04e14e84e84e0/Faith-Has-Its-Reasons-Integrative-Approaches-to-Defending-the-Christian-Faith-by-Kenneth-D-Boa.pdf
    • http://unieoooq.linkpc.net/24e14e34e04e74e5/Faith-amp-Fidelity-Faith-Love-amp-Devotion-1-by-Tere-Michaels.pdf
    • http://unieoooq.linkpc.net/14e04e04e94e94e5/Finding-Faith-Pirates-amp-Faith-4-by-Molly-Evangeline.pdf
    • http://unieoooq.linkpc.net/44e04e84e34e04e3/Crossed-Vol-7-Badlands-by-Christos-Gage.pdf
    • http://unieoooq.linkpc.net/44e84e74e54e14e2/Faith-and-Moonlight-Part-2-by-Mark-Gelineau.pdf