Malicious PDF — malware analysis report

Static analysis result for SHA-256 f742a4afb3cd4e71…

MALICIOUS

PDF

18.9 KB Created: 2019-04-30 05:29:29 +01:00 Authoring application: mPDF 5.7
MD5: 83fcf86be61d5bb77ed844f319e3ac5c SHA-1: a9c160fb47fda222694178c7fb18eb674afdffcb SHA-256: f742a4afb3cd4e71a50d7c77fb71cebc95e9867836a701cb4390904f6456154e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malware. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/34e14e04e24e2/Nights-and-Days-by-James-Merrill.pdf
    • http://unieoooq.linkpc.net/14e34e94e44e24e7/The-Changing-Light-at-Sandover-by-James-Merrill.pdf
    • http://unieoooq.linkpc.net/64e14e44e94e44e3/Molten-Salts-Chemistry-From-Lab-to-Applications-by-Frederic-Lantelme.pdf
    • http://unieoooq.linkpc.net/14e14e34e34e94e34e9/Scattering-Amplitudes-in-Gauge-Theories-by-Johannes-Henn.pdf
    • http://unieoooq.linkpc.net/84e54e44e64e54e0/Salts-of-Amino-Acids-Crystallization-Structure-and-Properties-by-Michel-Fleck.pdf
    • http://unieoooq.linkpc.net/74e94e04e74e24e9/Inverse-Acoustic-and-Electromagnetic-Scattering-Theory-by-David-Colton.pdf
    • http://unieoooq.linkpc.net/14e04e34e64e24e64e3/Compton-Scattering-Investigating-the-Structure-of-the-Nucleon-with-Real-Photons-by-Frank-Wissmann.pdf
    • http://unieoooq.linkpc.net/14e14e84e94e34e24e5/Electron-Scattering-in-Solid-Matter-A-Theoretical-and-Computational-Treatise-by-Robert-Hammerling.pdf
    • http://unieoooq.linkpc.net/74e34e64e14e04e9/Homemade-Bath-Bombs-Salts-and-Scrubs-300-Natural-Recipes-for-Luxurious-Soaks-by-Kate-Bello.pdf
    • http://unieoooq.linkpc.net/44e44e74e34e44e6/Salts-of-Silver-Toned-with-Gold-The-Harrison-D-Horblit-Collection-of-Early-Photography-by-Anne-Anninger.pdf
    • http://unieoooq.linkpc.net/14e04e34e04e44e94e3/A-Polarized-Discrete-Ordinate-Scattering-Model-for-Radiative-Transfer-Simulations-in-Spherical-Atmospheres-with-Thermal-Source-by-Claudia-Emde.pdf
    • http://unieoooq.linkpc.net/14e14e44e74e44e8/Lamikorda-by-D-R-Merrill.pdf
    • http://unieoooq.linkpc.net/14e14e14e24e94e6/Granted-by-Michelle-Merrill.pdf
    • http://unieoooq.linkpc.net/84e74e84e54e44e0/Southern-Tier-by-Arch-Merrill.pdf
    • http://unieoooq.linkpc.net/94e94e94e14e64e3/The-Psycho-Ex-Game-by-Merrill-Markoe.pdf
    • http://unieoooq.linkpc.net/24e14e04e84e44e6/Nose-Down-Eyes-Up-by-Merrill-Markoe.pdf
    • http://unieoooq.linkpc.net/14e94e74e84e84e4/Son-of-Eden-Tales-of-the-Guardian-1-by-Brianna-J-Merrill.pdf
    • http://unieoooq.linkpc.net/34e74e84e34e44e7/The-Inconvenient-Duchess-The-Radwells-1-by-Christine-Merrill.pdf
    • http://unieoooq.linkpc.net/74e34e84e84e0/Walking-in-Circles-Before-Lying-Down-by-Merrill-Markoe.pdf
    • http://unieoooq.linkpc.net/44e34e64e34e34e1/Daughter-of-Earth-Tales-of-the-Guardian-2-by-Brianna-J-Merrill.pdf
    • http://unieoooq.linkpc.net/14e14e84e94e34e24e5/Electron-Scattering-in-Solid-Matter-A-Theoretical-and-Computational-Treatise-by-R