Malicious PDF — malware analysis report

Static analysis result for SHA-256 63b403f1d75ec5d4…

MALICIOUS

PDF

16.1 KB Created: 2019-05-02 05:47:40 +01:00 Authoring application: mPDF 5.7
MD5: 4b633f54d5e32577cfac7b905b382a6a SHA-1: 5666913fa461afb3468603766a5eb9ca7b7504f7 SHA-256: 63b403f1d75ec5d476b8eadb948eaf9f5c6c9e2b0c000d8e45b1141396c4ebc9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently flagged as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e64e44e54e24e4/Dr-Monsoon-Taggert-s-Amazing-Finishing-Academy-by-Andrew-Matthews.pdf
    • http://unieoooq.linkpc.net/94e94e64e94e7/Monsoon-Love-and-Other-Nepali-Stories-by-Andrew-James-Pritchard.pdf
    • http://unieoooq.linkpc.net/44e54e54e64e44e7/As-You-Like-It-by-Andrew-Matthews.pdf
    • http://unieoooq.linkpc.net/14e64e44e54e24e3/Cat-Song-by-Andrew-Matthews.pdf
    • http://unieoooq.linkpc.net/34e44e34e24e04e6/Being-Happy-by-Andrew-Matthews.pdf
    • http://unieoooq.linkpc.net/34e84e74e64e84e9/The-Flip-Side-by-Andrew-Matthews.pdf
    • http://unieoooq.linkpc.net/94e44e54e34e2/Follow-Your-Heart-by-Andrew-Matthews.pdf
    • http://unieoooq.linkpc.net/44e84e14e24e34e1/Academy-X-by-Andrew-S-Trees.pdf
    • http://unieoooq.linkpc.net/44e64e94e14e24e8/Joseph-and-the-Amazing-Technicolor-Dreamcoat-by-Andrew-Lloyd-Webber.pdf
    • http://unieoooq.linkpc.net/14e04e64e04e64e44e1/Looney-Tunes-Treasury-Includes-Amazing-Interactive-Treasures-from-the-Warner-Bros-Vault-by-Andrew-Farago.pdf
    • http://unieoooq.linkpc.net/44e04e34e84e24e8/The-Academy-Making-of-a-Ruler-The-Eagle-King-s-Academy-1-by-C-C-Mon-.pdf
    • http://unieoooq.linkpc.net/14e04e54e84e64e34e3/An-academy-of-every-virtue-A-history-of-Mount-de-Sales-Academy-Catonsville-Maryland-1852-2002-by-Richard-C-Randt.pdf
    • http://unieoooq.linkpc.net/34e94e54e44e64e4/The-Princess-Montgomery-Taggert-8-by-Jude-Deveraux.pdf
    • http://unieoooq.linkpc.net/14e74e14e24e84e8/The-Duchess-Montgomery-Taggert-2-by-Jude-Deveraux.pdf
    • http://unieoooq.linkpc.net/44e44e64e74e04e9/The-Temptress-Montgomery-Taggert-3-by-Jude-Deveraux.pdf
    • http://unieoooq.linkpc.net/44e44e04e54e34e0/The-Academy-Book-2-The-Academy-2-by-Chad-Leito.pdf
    • http://unieoooq.linkpc.net/84e24e64e54e9/Mountain-Laurel-Montgomery-Taggert-5-by-Jude-Deveraux.pdf
    • http://unieoooq.linkpc.net/44e64e54e64e64e6/Star-Wars-Jedi-Academy-Return-of-the-Padawan-Jedi-Academy-2-by-Jeffrey-Brown.pdf
    • http://unieoooq.linkpc.net/14e44e74e24e54e4/Monsoon-Memories-by-Renita-D-39-Silva.pdf
    • http://unieoooq.linkpc.net/34e34e94e14e04e7/Chasing-The-Monsoon-by-Alexander-Frater.pdf