Malicious PDF — malware analysis report

Static analysis result for SHA-256 b73c180841daa6b8…

MALICIOUS

PDF

23.2 KB Created: 2019-05-02 17:02:01 +01:00 Authoring application: mPDF 5.7
MD5: a098c7b3e2c28797cdd893b51af3c2bb SHA-1: 0781157b68ad600bf3f183ade2e8c402c4be5be2 SHA-256: b73c180841daa6b80c3603faae03455f0a3ce30b1e9281f2a91c4991dda983a4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'unieoooq.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/54e84e14e54e34e4/The-Battle-of-the-Somme-A-Topographical-History-by-Gerald-Gliddon.pdf
    • http://unieoooq.linkpc.net/54e84e14e54e44e5/Somme-1916-Success-and-Failure-on-the-First-Day-of-the-Battle-of-the-Somme-by-Paul-Kendall.pdf
    • http://unieoooq.linkpc.net/84e74e64e94e74e7/The-History-of-the-Russo-Japanese-War-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-Battle-of-the-Japan-Sea-Peace-Treaty-by-Sydney-Tyler.pdf
    • http://unieoooq.linkpc.net/54e84e14e54e34e2/The-Battle-of-the-Somme-The-First-and-Second-Phase-by-John-Buchan.pdf
    • http://unieoooq.linkpc.net/24e44e34e14e6/The-Great-War-July-1-1916-The-First-Day-of-the-Battle-of-the-Somme-by-Joe-Sacco.pdf
    • http://unieoooq.linkpc.net/44e84e74e64e8/The-Face-Of-Battle-A-Study-Of-Agincourt-Waterloo-And-The-Somme-by-John-Keegan.pdf
    • http://unieoooq.linkpc.net/24e54e14e24e74e9/The-Face-of-Battle-A-Study-of-Agincourt-Waterloo-and-the-Somme-by-John-Keegan.pdf
    • http://unieoooq.linkpc.net/64e64e94e84e74e1/Battles-Involving-Hanover-Battle-of-Waterloo-Battle-of-Dettingen-Battle-of-Fontenoy-Battle-of-Tourcoing-Battle-of-Melle-by-Source-Wikipedia.pdf
    • http://unieoooq.linkpc.net/84e74e64e94e84e0/The-Russo-Japanese-War-Illustrated-Edition-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-of-the-Japan-Sea-Peace-Treaty-by-Sydney-Tyler.pdf
    • http://unieoooq.linkpc.net/14e14e24e14e44e5/A-History-of-Books-by-Gerald-Murnane.pdf
    • http://unieoooq.linkpc.net/64e34e54e04e84e8/A-History-of-the-Devil-by-Gerald-Messadi-.pdf
    • http://unieoooq.linkpc.net/14e04e04e34e94e2/The-Canadian-Prairies-A-History-by-Gerald-Friesen.pdf
    • http://unieoooq.linkpc.net/34e94e64e74e84e9/The-History-and-Topography-of-Ireland-by-Gerald-of-Wales.pdf
    • http://unieoooq.linkpc.net/44e04e24e34e54e7/Writing-To-Heal-by-Lee-Gliddon.pdf
    • http://unieoooq.linkpc.net/44e04e34e54e64e6/God-s-Bankers-A-History-of-Money-and-Power-at-the-Vatican-by-Gerald-Posner.pdf
    • http://unieoooq.linkpc.net/54e04e84e44e04e8/Karl-Marx-s-Theory-of-History-A-Defence-by-Gerald-A-Cohen.pdf
    • http://unieoooq.linkpc.net/24e64e84e84e04e9/The-Battle-A-New-History-of-Waterloo-by-Alessandro-Barbero.pdf
    • http://unieoooq.linkpc.net/14e14e74e14e94e84e4/Battle-Angel-Alita-Barjack-Battle-Angel-Battle-Angel-Alita-Chapters-Battle-Angel-Alita-Characters-Battle-Angel-Alita-Images-by-Source-Wikia.pdf
    • http://unieoooq.linkpc.net/74e44e84e64e14e4/The-Battle-of-Britain-Five-Months-That-Changed-History-May-October-1940-by-James-Holland.pdf
    • http://unieoooq.linkpc.net/24e54e64e74e54e4/The-Hinges-of-Battle-How-Change-and-Incompetence-Have-Changed-the-Face-of-History-by-Erik-Durschmied.pdf
    • http://unieoooq.linkpc.net/24e44e34e14e6/The-Great-War-July-1-1916-The-First-Day-of-the-Battle-of-the-Somme-by-