Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2ad61032c922cb6…

MALICIOUS

PDF

26.8 KB Created: 2019-04-30 03:25:46 +01:00 Authoring application: mPDF 5.7
MD5: 6cfd10c6d04a5780a6fe46361d05d22a SHA-1: ae484c7105281152ac2da4dd19e42b6449cfe979 SHA-256: c2ad61032c922cb6d0f973774cfe14dda942803ce35c7c3d856a1eac6993d4e6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, with the first identified URL being http://unieoooq.linkpc.net/94e04e24e44e14e0/Taran---Taylo-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-321-by-Jim-Emmett.pdf. This suggests the document's primary purpose is to lure users into clicking these links, potentially leading to further malicious downloads or phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9952

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/94e04e24e44e14e0/Taran---Taylo-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-321-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e44e14e4/T-C-E---Taran-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-320-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e44e94e4/Verno---View-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-339-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e54e44e0/Staub---Steph-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-312-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e44e14e5/Tronn---Turge-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-330-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e44e94e1/Smith---Socie-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-306-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e54e44e2/Schul---Scoti-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-295-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e54e44e3/Scoti---Seage-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-296-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/94e04e24e54e04e2/Wells---Westm-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-348-by-Jim-Emmett.pdf
    • http://unieoooq.linkpc.net/14e04e64e34e74e84e4/A-Catalogue-of-the-Personal-Library-of-Stephen-Girard-1750-1831-by-William-F-Zeil.pdf
    • http://unieoooq.linkpc.net/64e54e74e14e54e0/Catalogue-of-Sumptuous-Velours-Brocades-and-Embroideries-Fine-Old-Tapestries-Antique-Spanish-and-Italian-Laces-Silver-Sanctuary-Lamps-Curious-Early-Printed-Textiles-and-a-Series-of-Remarkable-Needlework-Pictures-All-of-Which-Are-the-Productions-of-T-by-American-Art-Association.pdf
    • http://unieoooq.linkpc.net/14e04e44e94e54e04e2/The-Church-Organist-s-Library-Vol-2-General-Use-by-Wayne-Leupold.pdf
    • http://unieoooq.linkpc.net/34e34e64e44e44e7/Harry-Potter-A-History-of-Magic-by-British-Library.pdf
    • http://unieoooq.linkpc.net/64e24e74e94e14e9/Ancient-Buddhist-Scrolls-from-Gandhara-The-British-Library-Kharosthi-Fragments-by-Richard-Salomon.pdf
    • http://unieoooq.linkpc.net/14e04e24e44e74e64e2/Annotated-Catalogue-Raisonn-of-the-Books-by-Martin-Kippenberger-1977-1997-by-Uwe-Koch.pdf
    • http://unieoooq.linkpc.net/14e14e94e84e54e74e7/Olaf-Nicolai---Sammlers-Blick-A-Catalogue-A-Catalogue-by-Boris-Groys.pdf
    • http://unieoooq.linkpc.net/14e94e64e14e44e3/Books-Can-Be-Deceiving-Library-Lover-s-Mystery-1-by-Jenn-McKinlay.pdf
    • http://unieoooq.linkpc.net/14e44e24e64e24e5/The-World-s-Best-Books-Taste-Culture-and-the-Modern-Library-by-Jay-Satterfield.pdf
    • http://unieoooq.linkpc.net/14e14e04e64e44e44e5/Mansfield-Park-Modern-Library-of-the-World-s-Best-Books-by-Jane-Austen.pdf
    • http://unieoooq.linkpc.net/24e94e84e44e74e5/The-Card-Catalog-Books-Cards-and-Literary-Treasures-by-Library-of-Congress.pdf
    • http://unieoooq.linkpc.net/94e04e24e54e44e0/Staub---Steph-Aus-The-British-Library-General-Catalogue-of-Printed-Books-to-1975-312-by-Jim-