Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2a462e0ee1511d2…

MALICIOUS

PDF

19.9 KB Created: 2019-05-02 10:37:29 +01:00 Authoring application: mPDF 5.7
MD5: 5ed92da47e63b309f8e6f29ac9e6fe4b SHA-1: 1f8519cc5c70b3230d99d3a752c94a4086a5693f SHA-256: c2a462e0ee1511d2a689a28c3b1bcf62af5c25ffa4d741c2896c9205dadb54a1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links pointing to external PDF files hosted on the 'unieoooq.linkpc.net' domain. This pattern is indicative of SEO poisoning or a link farm designed to drive traffic. While the specific content of the linked PDFs appears benign, the sheer volume and the use of a dynamic DNS domain suggest a malicious intent to manipulate search engine results or distribute unwanted content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e04e74e84e24e14e5/You-are-not-alone---Mein-Bruder-Michael-Jackson-by-Jermaine-Jackson.pdf
    • http://unieoooq.linkpc.net/84e94e44e74e0/You-Are-Not-Alone-Michael-Through-a-Brother-s-Eyes-by-Jermaine-Jackson.pdf
    • http://unieoooq.linkpc.net/94e34e34e24e14e9/Michael-Jackson-King-Of-Popweltweit-Einzige-Von-Michael-Jackson-Autorisierte-Fassung-by-Christian-Marks.pdf
    • http://unieoooq.linkpc.net/14e04e24e84e64e34e2/Michael-Jackson-s-Malt-Whiskey-Companion-by-Michael-Jackson.pdf
    • http://unieoooq.linkpc.net/54e14e74e94e94e3/Make-a-Joyful-Noise-Unto-the-Lord-The-Life-of-Mahalia-Jackson-Queen-of-Gospel-Singers-by-Jesse-Jackson.pdf
    • http://unieoooq.linkpc.net/94e84e54e74e04e6/Beer-by-Michael-Jackson.pdf
    • http://unieoooq.linkpc.net/44e74e24e44e9/Moonwalk-by-Michael-Jackson.pdf
    • http://unieoooq.linkpc.net/74e84e74e24e9/Percy-Jackson-Collection-Percy-Jackson-and-the-Lightning-Thief-the-Last-Olympian-the-Titans-Curse-the-Sea-of-Monsters-the-Battle-of-the-Labyrinth-the-Demigod-Files-and-the-Red-Pyramid-by-Rick-Riordan.pdf
    • http://unieoooq.linkpc.net/24e94e04e34e9/Jackson-Speed-The-Hero-of-El-Teneria-The-Jackson-Speed-Memoirs-1-by-Robert-R-Peecher-Jr-.pdf
    • http://unieoooq.linkpc.net/24e44e04e44e44e0/Percy-Jackson-and-the-Lightning-Thief-Percy-Jackson-and-the-Olympians-1-by-Rick-Riordan.pdf
    • http://unieoooq.linkpc.net/34e74e94e74e14e3/Charlie-Joe-Jackson-s-Guide-to-Making-Money-Charlie-Joe-Jackson-4-by-Tommy-Greenwald.pdf
    • http://unieoooq.linkpc.net/84e84e54e34e84e5/Michael-Jackson-by-Arno-Bani.pdf
    • http://unieoooq.linkpc.net/64e24e04e34e04e9/Michael-Jackson-Conspiracy-by-Aphrodite-Jones.pdf
    • http://unieoooq.linkpc.net/34e44e94e54e94e8/MJ-The-Genius-of-Michael-Jackson-by-Steve-Knopper.pdf
    • http://unieoooq.linkpc.net/54e44e94e24e14e6/Soledad-Brother-The-Prison-Letters-of-George-Jackson-by-George-L-Jackson.pdf
    • http://unieoooq.linkpc.net/84e64e34e34e1/Charlie-Joe-Jackson-s-Guide-to-Not-Reading-Charlie-Joe-Jackson-1-by-Tommy-Greenwald.pdf
    • http://unieoooq.linkpc.net/84e34e44e34e84e2/Michael-Jackson-Croyez-vous-bien-le-conna-tre-by-Max-Landry.pdf
    • http://unieoooq.linkpc.net/74e74e34e44e44e0/Whiskey-The-Definitive-World-Guide-by-Michael-James-Jackson.pdf
    • http://unieoooq.linkpc.net/14e04e64e44e34e74e7/Black-or-white-Michael-Jackson---die-ganze-Geschichte-by-Hanspeter-K-nzler.pdf
    • http://unieoooq.linkpc.net/44e24e64e04e24e9/Fathers-and-Children-Andrew-Jackson-and-the-Subjugation-of-the-American-Indian-by-Michael-Rogin.pdf
    • http://unieoooq.linkpc.net/74e84e74e24e9/Percy