Malicious PDF — malware analysis report

Static analysis result for SHA-256 d48580304be551be…

MALICIOUS

PDF

18.9 KB Created: 2019-04-30 17:34:14 +01:00 Authoring application: mPDF 5.7
MD5: ad9f44f8b1dae31dd9d266a1a8148f1b SHA-1: a2dbc125a061e2c4b3a021fe5b2d3c07ac8ef93c SHA-256: d48580304be551be16fb38e4d3f29c30738048f30f3788035b7e1f602101791f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a critical heuristic for containing a mass external link farm, with 25 links pointing to other PDFs. While the document body is heavily obfuscated, the presence of numerous links suggests a potential distribution or SEO poisoning attack. The ML classifier also strongly indicated maliciousness. No scripts were extracted, limiting further analysis of direct payload execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/54e84e54e74e9/Lady-s-Maid-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/14e14e74e94e24e64e6/Isa-amp-May-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/14e14e74e94e24e54e9/The-Memory-Box-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/24e44e54e64e84e1/Precious-Lives-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/34e44e14e94e64e7/Mother-Can-You-Hear-Me-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/24e04e04e74e64e5/Georgy-Girl-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/44e54e04e24e84e0/Diary-of-an-Ordinary-Woman-by-Margaret-Forster.pdf
    • http://unieoooq.linkpc.net/14e04e14e14e64e64e6/English-Countesses-Lady-Margaret-Beaufort-Joan-of-Kent-Joan-Beaufort-Countess-of-Westmorland-Bess-of-Hardwick-Lady-Catherine-Grey-by-Books-LLC.pdf
    • http://unieoooq.linkpc.net/14e14e74e94e34e04e1/Great-Novels-and-Short-Stories-of-E-M-Forster-by-E-M-Forster.pdf
    • http://unieoooq.linkpc.net/44e54e04e24e04e0/The-Sea-Lady-by-Margaret-Drabble.pdf
    • http://unieoooq.linkpc.net/34e04e34e94e44e6/Below-Stairs-The-Classic-Kitchen-Maid-s-Memoir-That-Inspired-quot-Upstairs-Downstairs-quot-and-quot-Downton-Abbey-quot-by-Margaret-Powell.pdf
    • http://unieoooq.linkpc.net/24e24e64e24e14e3/Lady-Oracle-by-Margaret-Atwood.pdf
    • http://unieoooq.linkpc.net/14e74e64e94e54e4/The-Pirate-And-His-Lady-by-Margaret-St-George.pdf
    • http://unieoooq.linkpc.net/64e84e54e44e74e0/Murder-at-the-Fete-Lady-Margaret-Turnbull-1-by-C-T-Mitchell.pdf
    • http://unieoooq.linkpc.net/44e04e04e64e64e1/Regency-Scandals-The-Mysterious-Miss-M-The-Captain-s-Lady-by-Margaret-McPhee.pdf
    • http://unieoooq.linkpc.net/34e34e84e44e64e8/Love-among-the-Butterflies-The-Travels-and-Adventures-of-a-Victorian-Lady-by-Margaret-Fountaine.pdf
    • http://unieoooq.linkpc.net/34e94e04e04e04e7/Love-Among-the-Butterflies-The-Secret-Life-of-a-Victorian-Lady-by-Margaret-Fountaine.pdf
    • http://unieoooq.linkpc.net/34e34e84e44e74e2/Butterflies-And-Late-Loves-The-Further-Travels-And-Adventures-Of-A-Victorian-Lady-by-Margaret-Fountaine.pdf
    • http://unieoooq.linkpc.net/24e94e84e94e04e6/Our-Lady-of-Birth-Control-A-Cartoonist-s-Encounter-with-Margaret-Sanger-by-Sabrina-Jones.pdf
    • http://unieoooq.linkpc.net/34e34e94e84e94e2/The-King-s-Mother-Lady-Margaret-Beaufort-Countess-of-Richmond-and-Derby-by-Michael-K-Jones.pdf
    • http://unieoooq.linkpc.net/14e14e74e94e34e04e1/Great-Novels-and-Short-Stories-of