Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcf0dad73224a7fc…

MALICIOUS

PDF

27.9 KB Created: 2019-04-30 03:29:34 +01:00 Authoring application: mPDF 5.7
MD5: 8b06ee5c44b53d39348c936d6ebd5770 SHA-1: 7655910804fefcffc38b48321b8a93a66d7e6872 SHA-256: dcf0dad73224a7fc724b2334729d33dc3fc94f0f5445110a50ff42430914c24b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the dynamic DNS domain 'unieoooq.linkpc.net'. This pattern is indicative of SEO poisoning or a traffic redirection scheme. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/84e34e74e34e74e5/Complex-Analysis-An-Introduction-to-The-Theory-of-Analytic-Functions-of-One-Complex-Variable-International-Series-in-Pure-amp-Applied-Mathematics-by-Lars-Valerian-Ahlfors.pdf
    • http://unieoooq.linkpc.net/14e04e94e64e64e94e0/Orthogonal-Functions-Moment-Theory-and-Continued-Fractions-Lecture-Notes-in-Pure-and-Applied-Mathematics-Lecture-Notes-in-Pure-and-Applied-Mathematics-by-A-Sri-Ranga.pdf
    • http://unieoooq.linkpc.net/84e34e74e34e74e4/Theory-of-Functions-of-a-Complex-Variable-by-Shanti-Narayan.pdf
    • http://unieoooq.linkpc.net/54e74e14e24e74e2/Complex-Analysis-I-Entire-and-Meromorphic-Functions-Polyanalytic-Functions-and-Their-Generalizations-No-1-by-Andrei-A-Gonchar.pdf
    • http://unieoooq.linkpc.net/74e94e94e44e84e2/Unifying-Themes-in-Complex-Systems-VI-Proceedings-of-the-Sixth-International-Conference-on-Complex-Systems-by-Ali-A-Minai.pdf
    • http://unieoooq.linkpc.net/74e94e94e44e84e1/Unifying-Themes-in-Complex-Systems-VII-Proceedings-of-the-Seventh-International-Conference-on-Complex-Systems-by-Ali-A-Minai.pdf
    • http://unieoooq.linkpc.net/54e74e14e24e74e0/Complex-Analysis-and-Spectral-Theory-Seminar-Leningrad-1979-80-by-Viktor-Petrovich-Khavin.pdf
    • http://unieoooq.linkpc.net/14e04e84e14e24e44e9/Complex-Systems-Design-amp-Management-Proceedings-of-the-Seventh-International-Conference-on-Complex-Systems-Design-amp-Management-Csd-amp-m-Paris-2016-by-Gauthier-Fanmuy.pdf
    • http://unieoooq.linkpc.net/14e04e84e14e24e54e1/Complex-Systems-Design-amp-Management-Proceedings-of-the-Fourth-International-Conference-on-Complex-Systems-Design-amp-Management-CSD-amp-M-2013-by-Marc-Aiguier.pdf
    • http://unieoooq.linkpc.net/14e14e54e24e94e44e5/The-Q--State-Potts-Model-Partition-Functions-and-Their-Zeros-in-the-Complex-Temperature--And-Q-Plane-by-Hubert-Klupfel.pdf
    • http://unieoooq.linkpc.net/94e54e54e14e64e9/Complex-Analysis-by-Eberhard-Freitag.pdf
    • http://unieoooq.linkpc.net/84e34e44e94e14e3/Complex-and-Chaotic-Nonlinear-Dynamics-Advances-in-Economics-and-Finance-Mathematics-and-Statistics-by-Thierry-Vialar.pdf
    • http://unieoooq.linkpc.net/84e44e74e24e44e7/Statistical-Modeling-and-Analysis-for-Complex-Data-Problems-by-Pierre-Duchesne.pdf
    • http://unieoooq.linkpc.net/14e14e34e74e24e74e4/Introduction-to-the-Analytic-Theory-of-Numbers-by-Raymond-Ayoub.pdf
    • http://unieoooq.linkpc.net/64e94e64e44e74e4/Theory-Of-Hypergeometric-Functions-Springer-Monographs-In-Mathematics-by-Kazuhiko-Aomoto.pdf
    • http://unieoooq.linkpc.net/94e94e94e84e34e1/Damages-in-International-Arbitration-Under-Complex-Long-Term-Contracts-by-Herfried-Woss.pdf
    • http://unieoooq.linkpc.net/54e74e14e24e64e8/Complex-Analysis-Operators-and-Related-Topics-The-S-A-Vinogradov-Memorial-Volume-by-Victor-P-Havin.pdf
    • http://unieoooq.linkpc.net/24e94e24e64e44e0/Complex-Adaptive-Systems-An-Introduction-to-Computational-Models-of-Social-Life-by-John-H-Miller.pdf
    • http://unieoooq.linkpc.net/94e64e74e44e1/Heroine-Complex-Heroine-Complex-1-by-Sarah-Kuhn.pdf
    • http://unieoooq.linkpc.net/34e94e74e34e3/The-Murder-Complex-The-Murder-Complex-1-by-Lindsay-Cummings.pdf
    • http://unieoooq.linkpc.net/74e94e94e44e84e2/Unifying-Themes-in-Complex-Systems-VI-Proceedings-of-the-S