Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4b3dc9cfb96ba10…

MALICIOUS

PDF

19.8 KB Created: 2019-05-07 04:42:26 +01:00 Authoring application: mPDF 5.7
MD5: 5de5bb240d5b1fc573b3f069615d911b SHA-1: 367b852450344dd8c48763e6b7b5f30bd7543968 SHA-256: e4b3dc9cfb96ba10f9120f4ca2e1797da1812d2d049fc323b0d2cc324c852316
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern observed is the creation of a link farm designed to direct users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/44e04e04e64e04e0/Birth-of-an-Island-by-Millicent-E-Selsam.pdf
    • http://unieoooq.linkpc.net/54e04e74e44e24e2/How-Kittens-Grow-by-Millicent-E-Selsam.pdf
    • http://unieoooq.linkpc.net/24e54e64e94e74e5/Creating-Your-Birth-Plan-The-Definitive-Guide-to-a-Safe-and-Empowering-Birth-by-Marsden-Wagner.pdf
    • http://unieoooq.linkpc.net/24e64e34e64e54e7/Millicent-Marie-Is-Not-My-Name-by-Karen-Pokras-Toz.pdf
    • http://unieoooq.linkpc.net/34e54e64e04e1/Cancer-It-can-be-a-lonely-journey-by-Ron-Millicent.pdf
    • http://unieoooq.linkpc.net/94e74e64e64e04e4/Geographie-Island-Vestmannaeyjar-Geographie-Islands-Vulkane-in-Island-Island-Plume-Sprengisandur-Islandisches-Hochland-by-Source-Wikipedia.pdf
    • http://unieoooq.linkpc.net/74e14e24e44e44e5/The-Birth-Date-Book-April-1-What-Your-Birth-Date-Reveals-about-You-by-Ariel-Books.pdf
    • http://unieoooq.linkpc.net/84e34e94e84e74e8/The-Birth-of-a-Tranny-PornStar-Volume-Two-Box-Set-of-Parts-4---6-The-Birth-of-a-Tranny-PornStar-Box-Sets-Book-2-by-Jenna-Masters.pdf
    • http://unieoooq.linkpc.net/84e34e24e74e34e5/Tropical-Island-Recovery-Cousine-Island-Seychelles-by-Michael-J-Samways.pdf
    • http://unieoooq.linkpc.net/94e74e84e14e34e6/Independent-Travellers-Greek-Island-Hopping-2006-The-Island-Hopper-s-Bible-by-Frewin-Poffley.pdf
    • http://unieoooq.linkpc.net/84e04e84e54e9/Once-On-This-Island-Mackinac-Island-Trilogy-1-by-Gloria-Whelan.pdf
    • http://unieoooq.linkpc.net/14e14e84e74e84e04e0/Easter-Island-Earth-Island-by-Paul-G-Bahn.pdf
    • http://unieoooq.linkpc.net/14e74e34e44e24e7/On-the-Island-On-the-Island-1-by-Tracey-Garvis-Graves.pdf
    • http://unieoooq.linkpc.net/44e94e84e94e44e2/On-the-Island-On-the-Island-1-by-Tracey-Garvis-Graves.pdf
    • http://unieoooq.linkpc.net/44e14e44e14e64e5/Island-Doctor-Island-Medics-1-by-Sue-Brown.pdf
    • http://unieoooq.linkpc.net/64e14e44e04e74e8/A-Trilogy-of-Island-Adventures-Robinson-Crusoe-The-Swiss-Family-Robinson-Treasure-Island-by-Daniel-Defoe.pdf
    • http://unieoooq.linkpc.net/24e14e64e54e94e7/Island-Escape-The-Island-0-5-by-Viv-Daniels.pdf
    • http://unieoooq.linkpc.net/24e04e24e54e44e8/Victoria-amp-Shannon-Gansett-Island-Episodes-1-Gansett-Island-15-25-by-Marie-Force.pdf
    • http://unieoooq.linkpc.net/94e74e64e44e24e5/Kultur-Island-Homosexualitat-in-Island-Islandische-Kuche-Islandische-Musik-Islandische-Sprache-Islandischer-Film-Kunst-by-Quelle-Wikipedia.pdf
    • http://unieoooq.linkpc.net/14e24e94e14e24e2/Tarragon-Island-Tarragon-Island-Series-by-Nikki-Tate.pdf
    • http://unieoooq.linkpc.net/84e34e94e84e74e8/The-Birth-of-a-Tranny-PornStar-Volume-Two-Box-Set-of-Parts-4---6-The-Birth-of-a-Tranny-PornStar-Box-Sets-