Malicious PDF — malware analysis report

Static analysis result for SHA-256 f0911be152788595…

MALICIOUS

PDF

24.3 KB Created: 2019-04-30 02:29:38 +01:00 Authoring application: mPDF 5.7
MD5: 51c0b422862533e8fbb78bb3fe2bf7f9 SHA-1: b41a9eefc83612bb6cfe275dcea7ebcef54dbe48 SHA-256: f0911be15278859522f1ab07354cc49bdfe5393af95b738138277d230bd46e2f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a critical heuristic for containing a mass external link farm, with 29 links identified. While many of these links point to seemingly benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO poisoning or to distribute further malware. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/54e14e54e44e0/A-Year-of-Living-Prayerfully-How-a-Curious-Traveler-Met-the-Pope-Walked-on-Coals-Danced-with-Rabbis-and-Revived-His-Prayer-Life-by-Jared-Brock.pdf
    • http://unieoooq.linkpc.net/14e04e34e74e94e64e8/The-Road-to-Dawn-Josiah-Henson-and-the-Story-That-Sparked-the-Civil-War-by-Jared-A-Brock.pdf
    • http://unieoooq.linkpc.net/94e24e14e44e64e8/A-Life-with-Karol-My-Forty-Year-Friendship-with-the-Man-Who-Became-Pope-by-Stanis-aw-Dziwisz.pdf
    • http://unieoooq.linkpc.net/34e74e14e84e24e6/The-Year-of-Living-Awkwardly-Sophomore-Year-Chloe-Snow-s-Diary-2-by-Emma-Chastain.pdf
    • http://unieoooq.linkpc.net/74e24e14e94e14e3/Pope-John-Paul-IIs-Theological-Journey-to-the-Prayer-Meeting-of-Religions-in-Assisi-Part-2-3-by-Johannes-D-rmann.pdf
    • http://unieoooq.linkpc.net/14e14e74e34e24e34e5/Living-Life-to-the-Fullest-with-Ehlers-Danlos-Syndrome-Guide-to-Living-a-Better-Quality-of-Life-While-Having-EDS-by-Kevin-Muldowney.pdf
    • http://unieoooq.linkpc.net/14e24e44e24e14e2/Phoebe-Pope-and-the-Year-of-Four-Phoebe-Pope-Novel-1-by-Nya-Jade.pdf
    • http://unieoooq.linkpc.net/74e34e94e44e24e9/A-Present-for-a-Papist-Or-the-History-of-the-Life-of-Pope-Joan-taken-Mainly-from-A-Cooke-s-Pope-Joane-by-Alexander-Cooke.pdf
    • http://unieoooq.linkpc.net/74e34e94e44e24e6/A-Present-for-a-Papist-Or-the-History-of-the-Life-of-Pope-Joan-Taken-Mainly-from-A-Cooke-s-Pope-Joane-by-Alexander-Cooke.pdf
    • http://unieoooq.linkpc.net/24e34e84e74e6/Batman-Year-100-by-Paul-Pope.pdf
    • http://unieoooq.linkpc.net/44e84e84e34e94e1/Living-On-A-Prayer-Lorraine-Hunt-3-by-Sheila-Quigley.pdf
    • http://unieoooq.linkpc.net/94e24e44e34e94e3/Intentional-Living-How-To-NOT-Die-With-Regrets-By-Living-A-Life-That-Matters-by-Simeon-Lindstrom.pdf
    • http://unieoooq.linkpc.net/44e44e24e84e94e8/Living-the-Farm-Sanctuary-Life-The-Ultimate-Guide-to-Eating-Mindfully-Living-Longer-and-Feeling-Better-Every-Day-by-Gene-Baur.pdf
    • http://unieoooq.linkpc.net/34e14e04e14e24e9/Lonesome-Traveler-The-Life-of-Lee-Hays-by-Doris-Willens.pdf
    • http://unieoooq.linkpc.net/84e44e34e04e34e2/The-Pope-and-the-Freemasons-The-Letter-quot-Humanum-Genus-quot-of-the-Pope-Leo-XIII-Against-Free-Masonry-and-the-Spirit-of-the-Age-by-Pope-Leo-XIII.pdf
    • http://unieoooq.linkpc.net/14e44e94e44e54e3/The-Year-of-Living-Dangerously-by-Christopher-J-Koch.pdf
    • http://unieoooq.linkpc.net/34e04e24e24e04e9/A-Country-Year-Living-the-Questions-by-Sue-Hubbell.pdf
    • http://unieoooq.linkpc.net/14e84e94e84e64e7/On-Prayer-And-The-Contemplative-Life-by-Thomas-Aquinas.pdf
    • http://unieoooq.linkpc.net/74e44e54e44e44e3/The-Pursuit-of-God-Extensions-of-His-Prayer-Life-by-A-W-Tozer.pdf
    • http://unieoooq.linkpc.net/34e64e24e64e84e4/Orthodox-Prayer-Life-The-Interior-Way-by--.pdf
    • http://unieoooq.linkpc.net/74e24e14e94e14e3/Pope-John-Paul-IIs-Theological-Journey-to-the-Prayer-Meeting-of-Religions-in-Assisi-Part-2-3-by-Johan