Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef98ab74a35a4997…

MALICIOUS

PDF

23.3 KB Created: 2019-04-29 23:05:05 +01:00 Authoring application: mPDF 5.7
MD5: 03c3791b2191cd3542b4bdebfe53d68e SHA-1: f7059a31167f137745ee8155bcd64242778adc96 SHA-256: ef98ab74a35a49974545f1cc120e77760e739fb3b6767e0f16be5dcb60f8e8dc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on a dynamic DNS domain. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier strongly supports the malicious verdict, and the PDF_SEO_LINK_FARM heuristic confirms the presence of numerous external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e44e14e64e94e5/Nazi-Nexus-America-s-Corporate-Connections-to-Hitler-s-Holocaust-by-Edwin-Black.pdf
    • http://unieoooq.linkpc.net/14e04e14e54e74e14e4/IBM-und-der-Holocaust-Die-Verstrickung-des-Weltkonzerns-in-die-Verbrechen-der-Nazis-by-Edwin-Black.pdf
    • http://unieoooq.linkpc.net/14e14e04e34e44e04e2/Hitler-s-Black-Victims-The-Historical-Experiences-of-Afro-Germans-European-Blacks-Africans-and-African-Americans-in-the-Nazi-Era-by-Clarence-Lusane.pdf
    • http://unieoooq.linkpc.net/34e24e84e54e54e3/Corporate-Crap-Lessons-Learned-from-40-Years-in-Corporate-America-by-Howard-Harrison.pdf
    • http://unieoooq.linkpc.net/94e44e04e24e74e4/Hitler-and-the-Holocaust-by-Robert-S-Wistrich.pdf
    • http://unieoooq.linkpc.net/94e34e94e94e74e1/Adolf-Hitler-and-the-Third-Reich-1933-1945-by-Robert-Edwin-Herzstein.pdf
    • http://unieoooq.linkpc.net/94e24e84e34e64e3/Adolf-Hitler-Dictator-of-Nazi-Germany-by-Brenda-Haugen.pdf
    • http://unieoooq.linkpc.net/94e64e54e04e4/Fate-Of-The-Children-Holocaust-Confessions-Of-A-Reluctant-Nazi-by-David-Matheny.pdf
    • http://unieoooq.linkpc.net/34e34e44e54e94e0/The-Nazi-Officer-s-Wife-How-One-Jewish-Woman-Survived-the-Holocaust-by-Edith-Hahn-Beer.pdf
    • http://unieoooq.linkpc.net/44e54e24e14e54e0/Hitler-s-Furies-German-Women-in-the-Nazi-Killing-Fields-by-Wendy-Lower.pdf
    • http://unieoooq.linkpc.net/44e04e04e54e64e8/Hitler-s-Willing-Executioners-Ordinary-Germans-and-the-Holocaust-by-Daniel-Jonah-Goldhagen.pdf
    • http://unieoooq.linkpc.net/34e84e34e54e74e9/Uncle-Hitler-A-Child-s-Traumatic-Journey-Through-Nazi-Hell-to-the-Safety-of-Britain-by-Alfred-Nestor.pdf
    • http://unieoooq.linkpc.net/44e84e64e74e34e8/The-Lion-and-the-Lamb-The-True-Holocaust-Story-of-a-Powerful-Nazi-Leader-and-a-Dutch-Resistance-Worker-by-Charles-Causey.pdf
    • http://unieoooq.linkpc.net/84e14e04e04e74e8/A-Mystic-in-Corporate-America-by-Robert-Rabbin.pdf
    • http://unieoooq.linkpc.net/14e04e14e14e34e6/Hitler-s-Cross-The-Revealing-Story-of-How-the-Cross-of-Christ-Was-Used-as-a-Symbol-of-the-Nazi-Agenda-by-Erwin-W-Lutzer.pdf
    • http://unieoooq.linkpc.net/74e14e14e04e54e0/Disruptors-Entrepreneurs-amp-the-Escape-from-Corporate-America-by-Kunal-Mehta.pdf
    • http://unieoooq.linkpc.net/54e04e84e04e84e0/Hitler-s-Jewish-Soldiers-The-Untold-Story-of-Nazi-Racial-Laws-and-Men-of-Jewish-Descent-in-the-German-Military-by-Bryan-Mark-Rigg.pdf
    • http://unieoooq.linkpc.net/14e94e14e54e04e4/America-Unchained-A-Freewheeling-Roadtrip-In-Search-Of-Non-Corporate-USA-by-Dave-Gorman.pdf
    • http://unieoooq.linkpc.net/94e84e14e74e74e8/Saboteurs-The-Nazi-Raid-on-America-by-Michael-Dobbs.pdf
    • http://unieoooq.linkpc.net/44e74e44e84e34e6/Predator-Nation-Corporate-Criminals-Political-Corruption-and-the-Hijacking-of-America-by-Charles-Ferguson.pdf
    • http://unieoooq.linkpc.net/94e34e94e94e74e1/Adolf-Hitler-and-the-Third-Reich-1933-1