Malicious PDF — malware analysis report

Static analysis result for SHA-256 f22f803eeb731dac…

MALICIOUS

PDF

20.1 KB Created: 2019-04-29 23:00:19 +01:00 Authoring application: mPDF 5.7
MD5: a4c3a58dcf7dbb4edd8f566069a15305 SHA-1: 45118cd6e591b9be4d2ac2e788625a3dc399cfd3 SHA-256: f22f803eeb731dacb4f057ac208905d41c8b4b98325b84504f7de01e693be4d9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking documents, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e14e94e84e54e54e5/Herndon-s-Lincoln-The-True-Story-of-a-Great-Life-the-History-and-Personal-Recollections-of-Abraham-Lincoln-Volume-4-by-William-Henry-Herndon.pdf
    • http://unieoooq.linkpc.net/14e14e24e94e34e74e0/Political-Debates-Between-Hon-Abraham-Lincoln-and-Hon-Stehen-A-Douglas---Scholar-s-Choice-Edition-by-Abraham-Lincoln.pdf
    • http://unieoooq.linkpc.net/34e04e14e74e84e0/The-Case-of-Abraham-Lincoln-A-Story-of-Adultery-Murder-and-the-Making-of-a-Great-President-by-Julie-M-Fenster.pdf
    • http://unieoooq.linkpc.net/24e14e54e54e94e8/The-Real-Lincoln-A-New-Look-at-Abraham-Lincoln-His-Agenda-and-an-Unnecessary-War-by-Thomas-J-DiLorenzo.pdf
    • http://unieoooq.linkpc.net/14e84e24e84e94e9/Abraham-Lincoln-s-Second-Inaugural-Address-by-Abraham-Lincoln.pdf
    • http://unieoooq.linkpc.net/54e94e24e24e64e9/Loving-Mr-Lincoln-The-Personal-Diaries-of-Mary-Todd-Lincoln-by-M-Kay-duPont.pdf
    • http://unieoooq.linkpc.net/44e14e24e14e94e0/Abraham-Lincoln-The-Great-Emancipator-by-Augusta-Stevenson.pdf
    • http://unieoooq.linkpc.net/14e54e04e74e34e0/Freedom-A-Novel-of-Abraham-Lincoln-and-the-Civil-War-by-William-Safire.pdf
    • http://unieoooq.linkpc.net/44e24e74e44e74e7/The-Great-Abraham-Lincoln-Pocket-Watch-Conspiracy-by-Jacopo-della-Quercia.pdf
    • http://unieoooq.linkpc.net/14e04e74e44e1/Abraham-Lincoln-Vampire-Hunter-Abraham-Lincoln-Vampire-Hunter-1-by-Seth-Grahame-Smith.pdf
    • http://unieoooq.linkpc.net/44e34e64e14e84e5/The-Autobiography-of-Abraham-Lincoln-by-Abraham-Lincoln.pdf
    • http://unieoooq.linkpc.net/54e94e64e04e04e3/Founders-Son-A-Life-of-Abraham-Lincoln-by-Richard-Brookhiser.pdf
    • http://unieoooq.linkpc.net/94e14e64e44e6/The-Gettysburg-Address-by-Abraham-Lincoln.pdf
    • http://unieoooq.linkpc.net/54e14e74e14e94e4/Recollected-Words-of-Abraham-Lincoln-by-Don-E-Fehrenbacher.pdf
    • http://unieoooq.linkpc.net/34e64e64e84e84e9/The-Impeachment-of-Abraham-Lincoln-by-Stephen-L-Carter.pdf
    • http://unieoooq.linkpc.net/34e94e14e94e74e2/The-Way-It-Spozed-to-Be-by-James-Herndon.pdf
    • http://unieoooq.linkpc.net/24e54e44e14e84e1/Abraham-Lincoln-and-the-Second-American-Revolution-by-James-M-McPherson.pdf
    • http://unieoooq.linkpc.net/54e94e64e04e44e1/A-Picture-Book-of-Abraham-Lincoln-by-David-A-Adler.pdf
    • http://unieoooq.linkpc.net/74e24e34e34e2/With-Malice-Toward-None-A-Biography-of-Abraham-Lincoln-by-Stephen-B-Oates.pdf
    • http://unieoooq.linkpc.net/24e54e44e14e64e3/Tried-by-War-Abraham-Lincoln-as-Commander-in-Chief-by-James-M-McPherson.pdf
    • http://unieoooq.linkpc.net/24e14e54e54e94e8/The-Real-Lincoln-A-New-Look-at-Abraham-Lincoln-His