Malicious PDF — malware analysis report

Static analysis result for SHA-256 808e294bae55627e…

MALICIOUS

PDF

21.2 KB Created: 2019-04-30 05:10:49 +01:00 Authoring application: mPDF 5.7
MD5: c76fc39816b28a08a041584cc05357cf SHA-1: 6be32bbe71a34eb30e70e2853e14d6848970b468 SHA-256: 808e294bae55627e90fecc3f4697107832e8d372e8de390217c64ee6eab0558c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used to distribute malicious content or engage in SEO poisoning. The ML classifier strongly indicated maliciousness. While the specific URLs appear benign, the sheer volume and structure suggest a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/34e84e44e84e94e1/Poilu-The-World-War-I-Notebooks-of-Corporal-Louis-Barthas-Barrelmaker-1914-1918-by-Louis-Barthas.pdf
    • http://unieoooq.linkpc.net/14e04e64e04e64e34e9/St-Louis-Missouri-Bauwerk-in-St-Louis-Person-St-Louis-Sport-St-Louis-Olympische-Sommerspiele-1904-Marilyn-Vos-Savant-by-Source-Wikipedia.pdf
    • http://unieoooq.linkpc.net/14e04e04e44e74e4/Ontario-and-the-First-World-War-1914-1918-A-Collection-of-Documents-by-Barbara-M-Wilson.pdf
    • http://unieoooq.linkpc.net/74e44e04e94e24e8/The-Journal-of-Louis-H-mon-by-Louis-H-mon.pdf
    • http://unieoooq.linkpc.net/64e14e24e84e64e8/The-Ocean-World-Being-a-Description-of-the-Sea-and-Some-of-Its-Inhabitants-by-Louis-Figuier.pdf
    • http://unieoooq.linkpc.net/64e54e24e44e74e1/Notebooks-1914-1916-by-Ludwig-Wittgenstein.pdf
    • http://unieoooq.linkpc.net/34e04e74e84e64e4/Jean-Louis-Cooking-with-the-Seasons-by-Jean-Louis-Palladin.pdf
    • http://unieoooq.linkpc.net/14e54e94e14e7/The-New-Poets-British-and-American-Poetry-Since-World-War-II-by-Macha-Louis-Rosenthal.pdf
    • http://unieoooq.linkpc.net/54e84e84e04e04e9/Strange-Case-of-Dr-Jekyll-and-Mr-Hyde-By-Robert-Louis-Stevenson---Illustrated-by-Robert-Louis-Stevenson.pdf
    • http://unieoooq.linkpc.net/14e14e24e64e74e04e8/The-Master-of-Ballantrae-by-Robert-Louis-Stevenson-Unabridged-1889-Original-by-Robert-Louis-Stevenson.pdf
    • http://unieoooq.linkpc.net/14e04e24e14e64e64e1/The-First-Air-War-1914-1918-by-Lee-B-Kennett.pdf
    • http://unieoooq.linkpc.net/84e14e34e94e74e0/The-Organ-Music-of-Louis-Lefebure-Wely-by-Louis-James-Alfred-Lefebure-Wely.pdf
    • http://unieoooq.linkpc.net/24e54e64e74e64e9/The-Great-War-in-Africa-1914-1918-by-Byron-Farwell.pdf
    • http://unieoooq.linkpc.net/34e44e44e34e64e3/Without-Warning-Ellen-s-Story-1914-1918-by-Dennis-Hamley.pdf
    • http://unieoooq.linkpc.net/14e94e44e64e34e3/Wounded-From-Battlefield-to-Blighty-1914-1918-by-Emily-Mayhew.pdf
    • http://unieoooq.linkpc.net/24e14e44e94e0/To-End-All-Wars-A-Story-of-Loyalty-and-Rebellion-1914-1918-by-Adam-Hochschild.pdf
    • http://unieoooq.linkpc.net/44e64e54e34e94e1/To-End-All-Wars-A-Story-of-Loyalty-and-Rebellion-1914-1918-by-Adam-Hochschild.pdf
    • http://unieoooq.linkpc.net/64e24e14e74e54e1/1914-1918-Quatre-Annees-Sur-Le-Front-Carnets-D-Un-Combattant-by-Paul-Tuffrau.pdf
    • http://unieoooq.linkpc.net/44e34e24e64e44e8/African-Kaiser-General-Paul-von-Lettow-Vorbeck-and-the-Great-War-in-Africa-1914-1918-by-Robert-Gaudi.pdf
    • http://unieoooq.linkpc.net/34e84e54e64e94e0/The-Western-Front-Companion-The-Complete-Guide-to-How-the-Armies-Fought-for-Four-Devastating-Years-1914-1918-by-Mark-Adkin.pdf
    • http://unieoooq.linkpc.net/64e14e24e84e64e8/The-Ocean-World-Being-a-Description-of-the-Se