Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca954562b702b74d…

MALICIOUS

PDF

24.2 KB Created: 2019-04-30 03:45:46 +01:00 Authoring application: mPDF 5.7
MD5: f0bf37ad4b0607cb293ed74a13229a1f SHA-1: 8592b414454c3b0289f2fe9f5a43e9f531e2740b SHA-256: ca954562b702b74db5a3dc4d56f16a514604f6e68a01203aafeef12f4222b140
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier and contains a large number of embedded links, indicating a potential SEO poisoning or link farm attack. While most extracted URLs were benign, the sheer volume and the critical heuristic firing suggest a malicious intent to distribute or redirect users. No scripts were extracted, limiting further analysis of the payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc
    • http://unieoooq.linkpc.net/74e84e14e64e9/Japanese-Tales-by-Royall-Tyler.pdf
    • http://unieoooq.linkpc.net/14e04e14e54e24e84e9/The-Tale-of-the-Heike-by-Royall-Tyler.pdf
    • http://unieoooq.linkpc.net/14e04e84e54e74e84e0/New-Englander-and-Yale-review-by-Edward-Royall-Tyler.pdf
    • http://unieoooq.linkpc.net/84e74e64e94e84e0/The-Russo-Japanese-War-Illustrated-Edition-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-of-the-Japan-Sea-Peace-Treaty-by-Sydney-Tyler.pdf
    • http://unieoooq.linkpc.net/14e04e54e44e24e04e9/Yuu-Sakura-japanese-cute-graviure-model-is-up-to-sexy-stage-she-has-big-busts-paparazzi-of-japanese-amateure-by-king-of-japanese-paparazzi.pdf
    • http://unieoooq.linkpc.net/44e84e54e34e64e4/Three-Japanese-Gothic-Tales-by-Ky-ka-Izumi.pdf
    • http://unieoooq.linkpc.net/14e04e24e74e94e9/Self-Inflicted-Wounds-Heartwarming-Tales-of-Epic-Humiliation-by-Aisha-Tyler.pdf
    • http://unieoooq.linkpc.net/84e24e24e54e54e1/Beyond-the-Rails-Six-Tales-of-Steampunk-Adventure-on-the-African-Frontier-by-Jack-Tyler.pdf
    • http://unieoooq.linkpc.net/34e34e74e14e84e7/The-Yellow-Jar-Two-Tales-From-Japanese-Tradition-by-Patrick-Atangan.pdf
    • http://unieoooq.linkpc.net/34e24e84e04e84e7/The-Moon-Maiden-and-Other-Japanese-Fairy-Tales-by-Grace-James.pdf
    • http://unieoooq.linkpc.net/84e74e64e94e74e7/The-History-of-the-Russo-Japanese-War-Complete-History-of-the-Conflict-Causes-of-the-War-Korean-Campaign-Naval-Operations-Battle-of-the-Yalu-Battle-Battle-of-the-Japan-Sea-Peace-Treaty-by-Sydney-Tyler.pdf
    • http://unieoooq.linkpc.net/44e94e54e74e04e3/Ambiguous-Bodies-Reading-the-Grotesque-in-Japanese-Setsuwa-Tales-by-Michelle-Li.pdf
    • http://unieoooq.linkpc.net/24e34e94e04e34e6/Japanese-Psyche-Major-Motifs-in-the-Fairy-Tales-of-Japan-by-Hayao-Kawai.pdf
    • http://unieoooq.linkpc.net/14e14e34e24e44e14e4/The-47-Ronin-Japanese-Tales-of-Vampires-Ghosts-and-Renegade-Samurai-by-Algernon-Bertram-Freeman-Mitford.pdf
    • http://unieoooq.linkpc.net/34e04e74e54e74e0/Tyler-s-Ultimate-Brilliant-Simple-Food-to-Make-Any-Time-by-Tyler-Florence.pdf
    • http://unieoooq.linkpc.net/34e24e74e64e74e6/Tokyo-Tales-A-Collection-of-Japanese-Short-Stories-Illustrations-by-Yoshimi-Ohtani-by-Renae-Lucas-Hall.pdf
    • http://unieoooq.linkpc.net/14e94e54e84e74e3/The-Trials-of-a-Scold-The-Incredible-True-Story-of-Writer-Anne-Royall-by-Jeff-Biggers.pdf
    • http://unieoooq.linkpc.net/14e14e34e94e94e24e7/Akane-Immigrant-Poet-English-amp-Japanese-Edition-The-Tanka-of-Mitsuko-Kasuga-a-Japanese-Immigrant-in-Mexico-by-Aiko-Chikaba.pdf
    • http://unieoooq.linkpc.net/34e24e94e14e74e1/Glen-amp-Tyler-s-Scottish-Troubles-Glen-amp-Tyler-2-by-J-B-Sanders.pdf
    • http://unieoooq.linkpc.net/94e44e64e54e34e6/Japanese-Fairy-Tales-By-Yei-Theodora-Ozaki---Illustrated-by-Yei-Theodora-Ozaki.pdf