Malicious PDF — malware analysis report

Static analysis result for SHA-256 e82e8459ba23253a…

MALICIOUS

PDF

21.8 KB Created: 2019-05-07 09:40:36 +01:00 Authoring application: mPDF 5.7
MD5: 66938b8d9a23253cf4f2d599cacc7529 SHA-1: 8aa65ff466607c7089ce4ce29c16382d9d77863b SHA-256: e82e8459ba23253ad2375162de3628efa619d54db9014215357c6dadf57bf90f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs are presented in a way that suggests a link farm, likely intended to direct users to external, potentially malicious, content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e14e74e04e94e64e4/Perpetrators-Victims-Bystanders-The-Jewish-Catastrophe-1933-1945-by-Raul-Hilberg.pdf
    • http://unieoooq.linkpc.net/64e94e14e14e1/The-Good-Old-Days-The-Holocaust-as-Seen-by-Its-Perpetrators-and-Bystanders-by-Ernst-Klee.pdf
    • http://unieoooq.linkpc.net/14e14e14e54e44e9/The-Destruction-of-the-European-Jews-by-Raul-Hilberg.pdf
    • http://unieoooq.linkpc.net/84e74e54e74e24e8/Widerstand-Und-Exil-1933-1945-by-Otto-R-Romberg.pdf
    • http://unieoooq.linkpc.net/14e14e74e14e14e44e9/A-Nightmare-in-History-The-Holocaust-1933-1945-by-Miriam-Chaikin.pdf
    • http://unieoooq.linkpc.net/14e04e04e54e64e34e9/Erlaubter-Humor-Im-Nationalsozialismus-1933-1945-by-Gudrun-Pausewang.pdf
    • http://unieoooq.linkpc.net/14e14e74e14e14e04e5/Nazism-and-German-Society-1933-1945-by-David-F-Crew.pdf
    • http://unieoooq.linkpc.net/14e14e74e64e74e44e5/Zuflucht-Auf-Widerruf-Exil-In-Italien-1933-1945-by-Klaus-Voigt.pdf
    • http://unieoooq.linkpc.net/94e44e74e34e44e8/Ich-will-Zeugnis-ablegen-bis-zum-Letzten-Tageb-cher-1933-1945-by-Victor-Klemperer.pdf
    • http://unieoooq.linkpc.net/54e14e74e64e14e3/Allianz-and-the-German-Insurance-Business-1933-1945-by-Gerald-D-Feldman.pdf
    • http://unieoooq.linkpc.net/94e34e94e94e74e1/Adolf-Hitler-and-the-Third-Reich-1933-1945-by-Robert-Edwin-Herzstein.pdf
    • http://unieoooq.linkpc.net/14e04e44e74e94e54e6/Emigrierte-Komponisten-in-Der-Medienlandschaft-Des-Exils-1933-1945-by-Nils-Grosch.pdf
    • http://unieoooq.linkpc.net/14e14e54e14e64e94e4/Widerstand-Und-Verfolgung-in-Hessen-1933-Bis-1945-Mikrofiche-Edition-Microform-by-Wolfgang-Form.pdf
    • http://unieoooq.linkpc.net/14e24e54e54e04e9/Whitehall-and-the-Jews-1933-1948-British-Immigration-Policy-Jewish-Refugees-and-the-Holocaust-by-Louise-London.pdf
    • http://unieoooq.linkpc.net/14e14e74e64e84e84e2/Zuflucht-Amerika-zur-Sozialgeschichte-der-Emigration-deutsch-j-discher-Frauen-in-die-USA-1933-1945-by-Sibylle-Quack.pdf
    • http://unieoooq.linkpc.net/14e04e94e44e84e94e3/-quot-bis-Alles-In-Scherben-F-llt-quot-Tagebuchbl-tter-1933---1945-by-Lili-Hahn.pdf
    • http://unieoooq.linkpc.net/24e34e64e24e6/A-Hidden-Childhood-A-Jewish-Girl-s-Sanctuary-in-a-French-Convent-1942-1945-by-Frida-Scheps-Weinstein.pdf
    • http://unieoooq.linkpc.net/54e14e34e54e64e6/The-United-States-Holocaust-Memorial-Museum-Encyclopedia-of-Camps-and-Ghettos-1933-1945-Ghettos-in-German-Occupied-Eastern-Europe-by-Geoffrey-P-Megargee.pdf
    • http://unieoooq.linkpc.net/14e04e64e64e24e74e8/Why-Jews-Do-What-They-Do-The-History-Of-Jewish-Customs-Throughout-The-Cycle-Of-The-Jewish-Year-by-Daniel-Sperber.pdf
    • http://unieoooq.linkpc.net/54e44e94e14e24e2/Suddenly-Jewish-Jews-Raised-as-Gentiles-Discover-Their-Jewish-Roots-by-Barbara-Kessel.pdf
    • http://unieoooq.linkpc.net/14e14e74e14e14e04e5