Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcbf3265dad06e49…

MALICIOUS

PDF

20.4 KB Created: 2019-05-01 18:31:59 +01:00 Authoring application: mPDF 5.7
MD5: d9ce2ff4ed5ff51a01630ea32d38539d SHA-1: fae475d756ff4a726b3b6099c1b4849f6ba316a3 SHA-256: fcbf3265dad06e4919db2cf1d272ed716b7c2896d30e2d1fd0f86834dbc1c700
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'unieoooq.linkpc.net'. This behavior is indicative of a link farm or a phishing lure designed to direct users to potentially malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/44e24e44e44e14e4/Seventh-Decimate-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/14e54e64e14e54e9/Mordant-s-Need-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/44e84e14e64e94e0/A-Man-Rides-Through-Mordant-s-Need-2-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/24e54e84e84e3/Reave-the-Just-and-Other-Tales-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/14e54e94e04e64e0/The-Gap-Into-Vision-Forbidden-Knowledge-Gap-2-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/44e64e24e74e64e8/The-Mirror-of-Her-Dreams-Mordant-s-Need-1-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/14e54e94e04e64e1/The-Gap-Into-Madness-Chaos-and-Order-Gap-4-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/34e04e64e74e74e8/The-Mirror-of-Her-Dreams-Mordant-s-Need-1-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/44e54e74e34e44e9/The-Mirror-of-Her-Dreams-Mordant-s-Need-1-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/34e24e64e54e34e5/The-One-Tree-The-Second-Chronicles-of-Thomas-Covenant-2-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/44e64e14e24e9/The-Wounded-Land-The-Second-Chronicles-of-Thomas-Covenant-1-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/94e44e94e14e04e2/Die-Pfade-des-Schicksals-The-Last-Chronicles-of-Thomas-Covenant-3-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/94e44e74e74e04e1/The-Wounded-Land-The-Second-Chronicles-of-Thomas-Covenant-Book-One-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/14e34e84e94e04e2/The-Power-That-Preserves-The-Chronicles-of-Thomas-Covenant-the-Unbeliever-3-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/14e74e74e44e74e3/Lord-Foul-s-Bane-The-Chronicles-of-Thomas-Covenant-the-Unbeliever-1-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/24e94e84e94e94e7/Lord-Foul-s-Bane-The-Chronicles-of-Thomas-Covenant-the-Unbeliever-1-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/14e64e34e14e94e8/The-Seventh-Throne-The-Rising-Dawn-Saga-3-by-Stephen-Zimmer.pdf
    • http://unieoooq.linkpc.net/94e44e74e64e04e5/The-First-amp-Second-Chronicles-of-Thomas-Covenant-the-Unbeliever-Thomas-Covenant-1-6-by-Stephen-R-Donaldson.pdf
    • http://unieoooq.linkpc.net/84e74e94e24e54e9/CPT-and-Lorentz-Symmetry-Proceedings-of-the-Seventh-Meeting-on-CPT-and-Lorentz-Symmetry-Seventh-Meeting-on-CPT-and-Lorentz-Symmetry-by-V-Alan-Kostelecky.pdf
    • http://unieoooq.linkpc.net/64e04e84e14e54e3/Zog-by-Julia-Donaldson.pdf