Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a6ebe1e47702feb…

MALICIOUS

PDF

19.8 KB Created: 2019-05-02 17:35:31 +01:00 Authoring application: mPDF 5.7
MD5: 650d6879266d25fb9b06bf88f1080c31 SHA-1: 2fd40e3f0e7caaae344fa44cdf618379698dbe84 SHA-256: 7a6ebe1e47702febf39c3703f3d52da38cff18cf3457e2d7a4538a4a7bc128be
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic identified the mass linking behavior. While the specific intent beyond linking is unclear due to the nature of the content, this pattern is indicative of a malicious distribution or redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/64e64e04e24e74e3/Jeff-Wall-Works-from-Munich-Collections-by-Inka-Graeve-Ingelmann.pdf
    • http://unieoooq.linkpc.net/14e14e24e04e64e94e6/Pulitzer-Prize-Winning-Works-Collections-11-Works-One-of-Ours-Alice-Adams-Anna-Christie-Miss-Lulu-Bett-by-Willa-Cather.pdf
    • http://unieoooq.linkpc.net/14e04e44e64e94e54e4/The-RETURN-of-the-INKA-A-Journey-of-Initiation-amp-Inka-Prophecies-for-2012-by-Elizabeth-B-Jenkins.pdf
    • http://unieoooq.linkpc.net/14e14e84e74e94e74e8/Munich-U-Bahn-Munich-U-Bahn-Stations-Munich-U-Bahn-Stubs-List-of-Munich-U-Bahn-Stations-Munchen-Hauptbahnhof-Munchen-Ost-Station-by-Books-LLC.pdf
    • http://unieoooq.linkpc.net/14e24e94e44e44e3/The-Wall-by-Jeff-Long.pdf
    • http://unieoooq.linkpc.net/94e84e04e44e34e6/From-Louise-Bourgeois-to-Jeff-Wall-Portraits-and-Studio-Stills-by-Elfie-Semotan-by-Museum-der-Moderne-Salzburg.pdf
    • http://unieoooq.linkpc.net/64e74e54e54e34e4/Works-by-Thomas-Pynchon-Novels-by-Thomas-Pynchon-Short-Story-Collections-by-Thomas-Pynchon-the-Crying-of-Lot-49-Gravity-s-Rainbow-by-Books-LLC.pdf
    • http://unieoooq.linkpc.net/64e64e04e24e54e9/The-Pacaa-Nova-Clash-of-Cultures-on-the-Brazilian-Frontier-by-Bernard-Von-Graeve.pdf
    • http://unieoooq.linkpc.net/64e24e94e14e44e7/Evasions-by-Inka-Tomi.pdf
    • http://unieoooq.linkpc.net/44e44e54e54e44e2/The-Wall-of-the-Sky-The-Wall-of-the-Eye-by-Jonathan-Lethem.pdf
    • http://unieoooq.linkpc.net/24e54e84e94e3/The-Wall-of-the-Sky-the-Wall-of-the-Eye-by-Jonathan-Lethem.pdf
    • http://unieoooq.linkpc.net/64e64e04e24e74e1/Veranstaltungen-organisieren-TaschenGuide-Haufe-TaschenGuide-by-Melanie-von-Graeve.pdf
    • http://unieoooq.linkpc.net/14e14e94e64e24e24e4/Ins-Herz-gestohlen-by-Inka-Loreen-Minden.pdf
    • http://unieoooq.linkpc.net/14e04e94e94e54e44e4/S-er-die-Glocken-by-Inka-Loreen-Minden.pdf
    • http://unieoooq.linkpc.net/94e34e04e64e14e7/Milans-bunte-Fl-gel-by-Inka-Mareila.pdf
    • http://unieoooq.linkpc.net/14e04e44e74e24e74e3/The-Language-of-the-Inka-Since-the-European-Invasion-by-Bruce-Mannheim.pdf
    • http://unieoooq.linkpc.net/14e04e44e74e24e74e6/The-Inka-Empire-A-Multidisciplinary-Approach-by-Izumi-Shimada.pdf
    • http://unieoooq.linkpc.net/14e04e44e74e14e14e0/A-Culture-of-Stone-Inka-Perspectives-on-Rock-by-Carolyn-Dean.pdf
    • http://unieoooq.linkpc.net/94e84e84e14e24e6/Nackt-und-schamlos-by-Sunny-Munich.pdf
    • http://unieoooq.linkpc.net/14e14e04e04e74e74e4/Das-geile-Mistst-ck-by-Sunny-Munich.pdf
    • http://unieoooq.linkpc.net/14e24e94e44e44e3/The-Wall-by-Jeff-Lo