Malicious PDF — malware analysis report

Static analysis result for SHA-256 c21e0513211a6ace…

MALICIOUS

PDF

27.0 KB Created: 2019-05-03 05:58:38 +01:00 Authoring application: mPDF 5.7
MD5: 80c113240be9c7430a9b53d6837ac05e SHA-1: a2d6232fb2853c31fd54871bfb4e1a5f475febd8 SHA-256: c21e0513211a6ace0bbc990009007b24d59f188ee2ab9c687265796570e496ae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs point to benign content, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO poisoning or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc
    • http://unieoooq.linkpc.net/94e84e64e04e74e3/Through-the-Shadowlands-A-Science-Writer-s-Odyssey-into-an-Illness-Science-Doesn-t-Understand-by-Julie-Rehmeyer.pdf
    • http://unieoooq.linkpc.net/24e34e74e44e24e9/A-Lethal-Inheritance-A-Mother-Uncovers-the-Science-behind-Three-Generations-of-Mental-Illness-by-Victoria-Costello.pdf
    • http://unieoooq.linkpc.net/74e34e54e84e4/The-Science-Fiction-Hall-of-Fame-Volume-Two-A-The-Greatest-Science-Fiction-Novellas-of-All-Time-Chosen-by-the-Members-of-The-Science-Fiction-Writers-of-America-by-Ben-Bova.pdf
    • http://unieoooq.linkpc.net/64e94e64e44e34e2/Space-Odyssey-an-Anthology-of-Great-Science-Fiction-Stories-by-Robert-Silverberg.pdf
    • http://unieoooq.linkpc.net/14e84e74e44e8/Mary-Shelley-Frankenstein-s-Creator-First-Science-Fiction-Writer-by-Joan-Kane-Nichols.pdf
    • http://unieoooq.linkpc.net/64e24e74e34e34e1/Tainted-How-Philosophy-of-Science-Can-Expose-Bad-Science-by-Kristin-Shrader-Frechette.pdf
    • http://unieoooq.linkpc.net/34e64e94e14e54e6/Science-and-Relativism-Some-Key-Controversies-in-the-Philosophy-of-Science-by-Larry-Laudan.pdf
    • http://unieoooq.linkpc.net/94e34e64e84e34e6/Three-Social-Science-Disciplines-in-Central-and-Eastern-Europe-Handbook-on-Economics-Political-Science-and-Sociology-1989-2001-by-Max-Kaase.pdf
    • http://unieoooq.linkpc.net/24e34e54e84e24e7/Why-Can-t-I-Make-People-Understand-Discovering-the-Validation-Those-with-Chrinic-Illness-Seek-and-Why-by-Lisa-J-Copen.pdf
    • http://unieoooq.linkpc.net/14e14e54e84e24e34e3/Regaining-Sanity-for-the-Earth-Why-Science-Needs-Best-Faith-to-Be-Responsible-Why-Faith-Needs-Best-Science-to-Be-Credible-by-Klaus-N-rnberger.pdf
    • http://unieoooq.linkpc.net/14e14e64e84e64e24e7/The-Defense-Science-Board-Task-Force-on-Human-Resources-Strategy-by-Defence-Science-Board.pdf
    • http://unieoooq.linkpc.net/84e84e34e94e94e5/NOVA-Science-Fiction-Magazin-23-Themenausgabe-Musik-und-Science-Fiction-by-Thomas-Ziegler.pdf
    • http://unieoooq.linkpc.net/64e14e54e34e44e9/La-science-pour-tous-Tous-ce-que-vous-devez-savoir-sur-la-science-TOME-1-by-M-Anctil.pdf
    • http://unieoooq.linkpc.net/44e44e54e94e24e9/Science-Fiction-Bundle-Over-500-Vintage-Science-Fiction-Short-Stories-by-Philip-K-Dick.pdf
    • http://unieoooq.linkpc.net/14e04e14e94e44e24e2/The-Science-of-Gettng-Rich-The-Science-of-Getting-Rich-in-the-21st-Century-by-Wallace-D-Wattles.pdf
    • http://unieoooq.linkpc.net/54e74e24e34e2/The-Science-of-Success-The-Secret-of-Getting-What-You-Want-WITH-The-Science-of-Getting-Rich-AND-The-Secret-by-Wallace-D-Wattles.pdf
    • http://unieoooq.linkpc.net/84e94e44e44e4/The-Science-of-Discworld-II-The-Globe-The-Science-of-Discworld-2-by-Terry-Pratchett.pdf
    • http://unieoooq.linkpc.net/24e94e24e34e14e6/Impossibility-The-Limits-of-Science-and-the-Science-of-Limits-by-John-D-Barrow.pdf
    • http://unieoooq.linkpc.net/24e54e94e94e8/Fantasy-amp-Science-Fiction-January-February-2015-The-Magazine-of-Fantasy-amp-Science-Fiction-717-by-Gordon-Van-Gelder.pdf
    • http://unieoooq.linkpc.net/24e74e34e54e8/Fantasy-amp-Science-Fiction-March-April-2014-The-Magazine-of-Fantasy-amp-Science-Fiction-712-by-Gordon-Van-Gelder.pdf