Malicious PDF — malware analysis report

Static analysis result for SHA-256 f31d29e49bee0be8…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 18:12:59 +01:00 Authoring application: mPDF 5.7
MD5: 854ef0374597f377e0b6d568d354e6f9 SHA-1: 0ab96336faa8f685f1cbb8440b99a9ed3b30fcca SHA-256: f31d29e49bee0be8254318f4decec76917bdcadbebf6ef8fb9ff8db4da85f29c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely for SEO spam or to distribute further malicious content. The document body is heavily obfuscated and unreadable, providing no direct clues to its purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/74e54e94e64e04e8/Adam-s-Return-The-Five-Promises-of-Male-Initiation-by-Richard-Rohr.pdf
    • http://unieoooq.linkpc.net/14e44e34e44e54e3/Simplicity-The-Freedom-of-Letting-Go-by-Richard-Rohr.pdf
    • http://unieoooq.linkpc.net/74e44e94e54e74e0/A-Lever-and-a-Place-to-Stand-The-Contemplative-Stance-the-Active-Prayer-by-Richard-Rohr.pdf
    • http://unieoooq.linkpc.net/14e04e44e64e94e54e4/The-RETURN-of-the-INKA-A-Journey-of-Initiation-amp-Inka-Prophecies-for-2012-by-Elizabeth-B-Jenkins.pdf
    • http://unieoooq.linkpc.net/34e44e04e04e94e2/Star-Wars-Infinities---Return-of-the-Jedi-by-Adam-Gallardo.pdf
    • http://unieoooq.linkpc.net/74e54e94e64e04e0/The-Initiation-by-Paul-J-Sneddon-by-The-Initiation.pdf
    • http://unieoooq.linkpc.net/24e94e54e64e94e5/Threesomes-Male-Female-Male-by-Darren-G-Burton.pdf
    • http://unieoooq.linkpc.net/14e14e44e34e64e34e2/Promises-Promises-Princess-Luanne-and-Wizard-Heatheria-by-Charles-A-Johnson.pdf
    • http://unieoooq.linkpc.net/64e24e94e94e0/God-s-Promises-For-You-Divine-Promises-and-Affirmations-For-Your-Success-All-round-Prosperity-and-Total-Well-being-by-Theo-John-Paul.pdf
    • http://unieoooq.linkpc.net/64e54e44e74e84e0/Return-to-the-Fatherland-by-Richard-Paraiso.pdf
    • http://unieoooq.linkpc.net/54e94e14e94e14e9/Kickboxing-The-Cross-Hook-And-Uppercut-From-Initiation-To-Knockout-Everything-You-Need-To-Know-and-more-To-Master-The-Pain-Game-Kickboxing-From-Initiation-To-Knockout-by-Martina-Sprague.pdf
    • http://unieoooq.linkpc.net/14e24e04e74e64e6/The-Coming-Return-of-the-Yahweh-by-Richard-Vadim.pdf
    • http://unieoooq.linkpc.net/74e24e14e14e6/Promises-Linger-Promises-1-by-Sarah-McCarty.pdf
    • http://unieoooq.linkpc.net/24e54e74e54e94e7/Male-Seeking-Male-by-Kathleen-Lee.pdf
    • http://unieoooq.linkpc.net/64e54e64e84e34e4/Male-Male-by-Seth-King.pdf
    • http://unieoooq.linkpc.net/24e54e14e64e5/I-Remember-Lemuria-And-The-Return-Of-Sathanas-Forgotten-Books-by-Richard-S-Shaver.pdf
    • http://unieoooq.linkpc.net/14e94e24e34e64e2/Making-Promises-Promises-2-by-Amy-Lane.pdf
    • http://unieoooq.linkpc.net/84e24e14e04e74e1/The-Power-of-Return-Return-to-Me-That-I-May-Return-to-You-Zech-1-3-by-John-Goyette.pdf
    • http://unieoooq.linkpc.net/44e94e04e44e94e9/American-Pharaoh-Mayor-Richard-J-Daley---His-Battle-for-Chicago-and-the-Nation-by-Adam-Cohen.pdf
    • http://unieoooq.linkpc.net/24e94e44e14e74e6/A-is-for-Alpha-Male-A-is-for-Alpha-Male-1-by-Laurel-Ulen-Curtis.pdf
    • http://unieoooq.linkpc.net/64e24e94e94e0/God-s-Promi