Malicious PDF — malware analysis report

Static analysis result for SHA-256 baa8a1e26bbc25e2…

MALICIOUS

PDF

21.7 KB Created: 2019-05-01 19:21:21 +01:00 Authoring application: mPDF 5.7
MD5: 834b6910e8bb149fb9e05fff00dd8f1d SHA-1: 80aa48069c8ceee4a050552881e10aefe94dac81 SHA-256: baa8a1e26bbc25e2abd124616316ce38ca9b5a596c2a3004df27651fb9d99bd0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'unieoooq.linkpc.net'. This heuristic firing, combined with the ML classifier's high confidence, suggests a link-farming or redirection attack. No scripts were extracted from this sample, and the document body was unreadable, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e14e74e04e14e64e4/The-Making-of-the-Oxford-English-Dictionary-by-Peter-Gilliver.pdf
    • http://unieoooq.linkpc.net/14e04e34e54e44e34e7/The-Oxford-Dictionary-of-Current-English-by-Jennifer-Seidl.pdf
    • http://unieoooq.linkpc.net/44e34e34e24e04e0/The-Concise-Oxford-English-Arabic-Dictionary-of-Current-Usage-by-N-S-Doniach.pdf
    • http://unieoooq.linkpc.net/94e94e84e54e74e3/The-Dictionary-of-Disagreeable-English-A-Curmudgeon-s-Compendium-of-Excruciatingly-Correct-Grammar-by-Robert-Hartwell-Fiske.pdf
    • http://unieoooq.linkpc.net/24e54e74e24e24e6/The-Compact-Edition-of-the-Oxford-English-Dictionary-2-Vols-w-Reading-Glass-by-Herbert-Coleridge.pdf
    • http://unieoooq.linkpc.net/24e14e44e64e54e3/The-Professor-and-the-Madman-A-Tale-of-Murder-Insanity-and-the-Making-of-the-Oxford-English-Dictionary-by-Simon-Winchester.pdf
    • http://unieoooq.linkpc.net/54e04e54e14e04e9/The-Professor-and-the-Madman-A-Tale-of-Murder-Insanity-and-the-Making-of-the-Oxford-English-Dictionary-by-Simon-Winchester.pdf
    • http://unieoooq.linkpc.net/74e14e14e74e64e3/Higher-Lessons-in-English-A-Work-on-English-Grammar-and-Composition-in-Which-the-Science-of-the-Language-Is-Made-Tributary-to-the-Art-of-Expres-by-Alonzo-Reed.pdf
    • http://unieoooq.linkpc.net/24e74e54e94e54e5/The-Oxford-Dictionary-of-Idioms-by-Judith-Siefring.pdf
    • http://unieoooq.linkpc.net/24e74e54e74e94e3/The-Oxford-Dictionary-of-Quotations-by-Elizabeth-Knowles.pdf
    • http://unieoooq.linkpc.net/54e14e24e84e14e0/Canadian-Oxford-Dictionary-by-Katherine-Barber.pdf
    • http://unieoooq.linkpc.net/94e44e14e94e94e8/Norwegian-English-Dictionary-A-Pronouncing-and-Translating-Dictionary-of-Modern-Norwegian-Bokm-l-and-Nynorsk-with-a-Historical-and-Grammatical-Introduction-by-Einar-Ingvald-Haugen.pdf
    • http://unieoooq.linkpc.net/14e14e04e24e34e54e2/The-Oxford-Dictionary-of-Nursery-Rhymes-by-Iona-Opie.pdf
    • http://unieoooq.linkpc.net/24e74e54e94e74e3/The-Oxford-Dictionary-of-American-Usage-and-Style-by-Bryan-A-Garner.pdf
    • http://unieoooq.linkpc.net/64e94e84e94e94e0/The-New-Oxford-Picture-Dictionary-Beginners-Workbook-by-Patricia-E-Zevin.pdf
    • http://unieoooq.linkpc.net/24e44e44e84e3/Brave-New-Words-The-Oxford-Dictionary-of-Science-Fiction-by-Jeff-Prucher.pdf
    • http://unieoooq.linkpc.net/84e24e04e74e14e6/A-Tagalog-English-and-English-Tagalog-Dictionary---Scholar-s-Choice-Edition-by-Charles-Nigg.pdf
    • http://unieoooq.linkpc.net/54e84e14e64e14e8/A-Grammar-of-Present-Day-English-by-Friedrich-Ungerer.pdf
    • http://unieoooq.linkpc.net/54e84e44e34e84e0/English-Grammar-and-Composition-Complete-Course-by-John-E-Warriner.pdf
    • http://unieoooq.linkpc.net/94e74e34e14e04e5/Focus-on-Grammar-Split-4b-with-Mylab-English-by-Marjorie-Fuchs.pdf
    • http://unieoooq.linkpc.net/24e14e44e64e54e3/The-Professor-and-the-Madman-A-Tale-of-Murder-Insanity-and-the-Making-of-the-Oxford-English-D