Malicious PDF — malware analysis report

Static analysis result for SHA-256 d204e3f1bbf73edd…

MALICIOUS

PDF

20.3 KB Created: 2019-05-01 18:30:52 +01:00 Authoring application: mPDF 5.7
MD5: 5c47cf547702743e02c8d10b3863d7fd SHA-1: 1f68f044f77e185ab2b1a998d8f36878e4e7190a SHA-256: d204e3f1bbf73edd1f9406a5473b891510a2fb081d593ec22800d7750a93fb74
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of external links, indicating a potential SEO manipulation or content distribution scheme. The embedded URLs, while marked as benign in some cases, are part of a link farm. No scripts were extracted from this sample, limiting the ability to determine a more specific attack pattern or family.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.l
    • http://unieoooq.linkpc.net/44e04e54e64e14e3/Lord-John-and-the-Private-Matter-Lord-John-Grey-1-by-Diana-Gabaldon.pdf
    • http://unieoooq.linkpc.net/34e04e04e04e74e7/Lord-John-and-the-Private-Matter-by-Diana-Gabaldon.pdf
    • http://unieoooq.linkpc.net/44e64e54e04e9/Lord-John-and-the-Hand-of-Devils-Lord-John-Grey-0-5-1-5-2-5-by-Diana-Gabaldon.pdf
    • http://unieoooq.linkpc.net/44e04e84e34e54e4/Lord-John-and-the-Brotherhood-of-the-Blade-Lord-John-Grey-2-by-Diana-Gabaldon.pdf
    • http://unieoooq.linkpc.net/34e04e04e04e84e0/Lord-John-and-the-Brotherhood-of-the-Blade-by-Diana-Gabaldon.pdf
    • http://unieoooq.linkpc.net/34e54e04e94e94e7/Cadmon-The-Lord-s-Poet-by-John-K-Deaconson.pdf
    • http://unieoooq.linkpc.net/34e74e34e14e34e0/Lord-Byron-s-Novel-The-Evening-Land-by-John-Crowley.pdf
    • http://unieoooq.linkpc.net/24e94e84e34e24e1/Lord-Byron-s-Novel-The-Evening-Land-by-John-Crowley.pdf
    • http://unieoooq.linkpc.net/74e44e74e84e4/The-Fear-of-the-Lord-Discover-the-Key-to-Intimately-Knowing-God-by-John-Bevere.pdf
    • http://unieoooq.linkpc.net/74e24e24e44e04e8/For-the-Lord-We-Love-Your-Study-Guide-to-the-Lausanne-Covenant-by-John-R-W-Stott.pdf
    • http://unieoooq.linkpc.net/14e14e74e84e14e34e9/Food-for-the-Road-Life-Lessons-from-the-Lord-s-Table-by-John-van-de-Laar.pdf
    • http://unieoooq.linkpc.net/34e64e54e54e74e8/PART-TWO---The-Window-of-the-Lord-s-Return-The-Unfolding-Signs-of-the-End-Times-by-John-Shorey.pdf
    • http://unieoooq.linkpc.net/44e64e84e84e74e3/Grey-God-Demon-Lord-3-by-T-C-Southwell.pdf
    • http://unieoooq.linkpc.net/14e04e44e74e14e1/The-Pirate-Lord-Lord-Trilogy-1-by-Sabrina-Jeffries.pdf
    • http://unieoooq.linkpc.net/94e54e74e04e34e2/The-History-of-the-Church-of-Scotland-Beginning-in-the-Year-of-Our-Lord-203-and-Continued-to-the-End-of-the-Reign-of-King-James-the-VI-of-Ever-Blessed-Memory-Wherein-Are-Described-the-Progress-of-Christianity-The-Persecutions-and-Interruptions-of-It-by-John-Spotswood.pdf
    • http://unieoooq.linkpc.net/24e64e54e04e74e6/The-Last-Lord-of-Paradise-Generation-One-Jeanne-and-Anton-The-Last-Lord-of-Paradise-a-Family-Saga-of-Early-Michigan-French-1-by-Vivian-LeMay.pdf
    • http://unieoooq.linkpc.net/14e74e34e44e04e2/Lord-Peter-Views-the-Body-Lord-Peter-Wimsey-4-by-Dorothy-L-Sayers.pdf
    • http://unieoooq.linkpc.net/54e34e94e94e14e7/Lord-Peter-Views-the-Body-Lord-Peter-Wimsey-4-by-Dorothy-L-Sayers.pdf
    • http://unieoooq.linkpc.net/34e04e74e74e54e7/Dark-Lord-of-Derkholm-Derkholm-1-by-Diana-Wynne-Jones.pdf
    • http://unieoooq.linkpc.net/64e14e04e94e64e4/The-Love-Poems-of-Lord-Byron-A-Romantic-s-Passion-by-Lord-Byron.pdf