Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbe622b9257bd83f…

MALICIOUS

PDF

28.5 KB Created: 2019-04-30 04:25:21 +01:00 Authoring application: mPDF 5.7
MD5: 9a0a0690e4388df2885c01d33a9facc7 SHA-1: c9a4c4148f6bb70fbb46a9648e484d75462fff5d SHA-256: bbe622b9257bd83fb5702263fe11efd14f66c1a14551e6e381ad689c59606e7e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, hosted on a dynamic DNS domain. This technique is often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the suspicious link structure. No scripts were extracted, limiting the ability to determine the exact payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/74e54e04e74e84e4/A-Sermon-Preached-at-the-Funeral-of-the-Right-Honourable-the-Lady-Margaret-Mainard-at-Little-Easton-in-Essex-on-the-30th-of-June-1682-by-Tho-Ken-1682-by-Thomas-Ken.pdf
    • http://unieoooq.linkpc.net/74e54e04e74e84e3/A-Sermon-Preached-at-the-Funeral-of-the-Right-Honourable-the-Lady-Margaret-Mainard-at-Little-Easton-in-Essex-on-the-30th-of-June-1682-by-Thomas-Lord-Bishop-of-Bath-and-Wells-1688-by-Thomas-Ken.pdf
    • http://unieoooq.linkpc.net/14e34e94e24e44e9/An-Enlightened-Duke-The-Life-of-Archibald-Campbell-1682---1761-Earl-of-Ilay-3rd-Duke-of-Argyll-by-Roger-L-Emerson.pdf
    • http://unieoooq.linkpc.net/14e14e64e34e34e34e6/A-Few-English-Notes-on-a-Late-Sermon-Preached-Before-the-Sons-of-the-Clergy-by-Dr-Bisse-Intended-to-Vindicate-the-English-Reformation-from-the-Charge-of-Sacrilege-in-a-Letter-to-the-Reverend-Dr------Dean-of------by-John-Lewis.pdf
    • http://unieoooq.linkpc.net/14e14e64e34e24e24e1/The-Beauty-of-Holiness-in-the-Common-Prayer-As-Set-Forth-in-Four-Sermons-Preached-at-the-Rolls-by-Thomas-Bisse.pdf
    • http://unieoooq.linkpc.net/64e44e04e74e24e8/Sermon-to-the-Princes-by-Thomas-M-ntzer.pdf
    • http://unieoooq.linkpc.net/74e64e14e44e1/Funeral-for-a-Dog-by-Thomas-Pletzinger.pdf
    • http://unieoooq.linkpc.net/64e44e04e64e44e7/A-Sermon-On-Acts-XIII-22-Preach-d-on-January-20-1714-15-by-a-Clergyman-in-the-Country-by-Sermon.pdf
    • http://unieoooq.linkpc.net/14e04e34e84e74e34e8/John-Thomas-and-Lady-Jane-The-Second-Version-of-Lady-Chatterley-s-Lover-by-D-H-Lawrence.pdf
    • http://unieoooq.linkpc.net/64e84e24e44e84e0/Easton-in-the-Valley-Easton-2-by-Rebecca-Price-Janney.pdf
    • http://unieoooq.linkpc.net/14e04e14e14e64e64e6/English-Countesses-Lady-Margaret-Beaufort-Joan-of-Kent-Joan-Beaufort-Countess-of-Westmorland-Bess-of-Hardwick-Lady-Catherine-Grey-by-Books-LLC.pdf
    • http://unieoooq.linkpc.net/14e14e64e34e24e84e3/A-Sermon-Preach-d-at-St-Philip-s-Church-in-Birmingham-August-9-1724-At-the-Opening-of-a-Charity-School-Built-to-Receive-an-Hundred-Children-Which-Are-There-Not-Only-to-Be-Taught-and-Cloath-d-But-Also-Fed-and-Lodg-d-With-Accommodations-for-a-Master-by-Thomas-Bisse.pdf
    • http://unieoooq.linkpc.net/14e74e74e14e44e7/June-the-Prune-and-Lady-Bird-Cancer-Stinks-Kids-and-Pets-Cracking-the-Power-Code-by-Gracie-Bradford.pdf
    • http://unieoooq.linkpc.net/44e54e04e24e04e0/The-Sea-Lady-by-Margaret-Drabble.pdf
    • http://unieoooq.linkpc.net/34e14e34e14e54e6/Adventures-in-Funeral-Crashing-Funeral-Crashing-1-by-Milda-Harris.pdf
    • http://unieoooq.linkpc.net/14e74e64e94e54e4/The-Pirate-And-His-Lady-by-Margaret-St-George.pdf
    • http://unieoooq.linkpc.net/24e24e64e24e14e3/Lady-Oracle-by-Margaret-Atwood.pdf
    • http://unieoooq.linkpc.net/54e84e54e74e9/Lady-s-Maid-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/64e84e54e44e74e0/Murder-at-the-Fete-Lady-Margaret-Turnbull-1-by-C-T-Mitchell.pdf
    • http://unieoooq.linkpc.net/34e94e04e04e04e7/Love-Among-the-Butterflies-The-Secret-Life-of-a-Victorian-Lady-by-Margaret-Fountaine.pdf
    • http://unieoooq.linkpc.net/14e34e94e24e44e9/An-Enlightened-Duke-The-Life-of-Archibald-Campbell-1682---1761-Earl-of