Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd393ebff038f49d…

MALICIOUS

PDF

19.6 KB Created: 2019-05-02 01:58:47 +01:00 Authoring application: mPDF 5.7
MD5: 1537b5713baf6135b7855336a56e9c9e SHA-1: 858494dd1536a1d6db0db85ef938f4e121632c8f SHA-256: fd393ebff038f49db882bd59e34c195c7b3cf067ad4b52316ffde5172d0cc8a7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a multitude of external PDF documents, likely as a form of SEO abuse or to host malicious content. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/64e74e64e84e34e1/Phobos-The-Journey-Through-and-Beyond-Fear-The-Journey-Through-and-Beyond-Fear-by-MR-Mark-J-Terrell.pdf
    • http://unieoooq.linkpc.net/34e24e14e44e74e4/Hijacked-By-Fear-Real-Solutions-for-Fear-Anxiety-and-Increasing-Confidence-by-Mark-Hochwender.pdf
    • http://unieoooq.linkpc.net/84e44e14e84e0/Journey-Into-Fear-by-Eric-Ambler.pdf
    • http://unieoooq.linkpc.net/34e04e44e84e24e6/Journey-into-Mystery-Fear-Itself-Fallout-by-Kieron-Gillen.pdf
    • http://unieoooq.linkpc.net/74e44e34e44e74e9/Lighthouse-of-Hope-A-Motivational-Christianity-Self-help-Day-by-Day-Journey-to-Fear-Free-Living-by-Sue-Falcone.pdf
    • http://unieoooq.linkpc.net/24e74e14e64e84e9/Fear-Fighters-How-to-Live-With-Confidence-in-a-World-Driven-by-Fear-by-Jentezen-Franklin.pdf
    • http://unieoooq.linkpc.net/14e04e14e34e04e2/Fear-Busters-14-Ways-to-Kick-Fear-to-the-Curb-by-Thomas-Miller.pdf
    • http://unieoooq.linkpc.net/44e14e34e84e7/Chill-of-Fear-Bishop-Special-Crimes-Unit-8-Fear-2-by-Kay-Hooper.pdf
    • http://unieoooq.linkpc.net/84e74e04e34e5/Sleeping-with-Fear-Bishop-Special-Crimes-Unit-9-Fear-3-by-Kay-Hooper.pdf
    • http://unieoooq.linkpc.net/44e54e14e44e7/Hunting-Fear-Bishop-Special-Crimes-Unit-7-Fear-1-by-Kay-Hooper.pdf
    • http://unieoooq.linkpc.net/14e24e84e84e44e1/Fear-the-Future-The-Fear-Saga-3-by-Stephen-Moss.pdf
    • http://unieoooq.linkpc.net/14e94e74e14e8/Queer-Fear-II-Queer-Fear-2-by-Michael-Rowe.pdf
    • http://unieoooq.linkpc.net/34e44e34e54e84e9/The-Artist-s-Journey-The-Wake-of-the-Hero-s-Journey-and-the-Lifelong-Pursuit-of-Meaning-by-Steven-Pressfield.pdf
    • http://unieoooq.linkpc.net/64e04e14e14e34e8/Autobiography-Volume-1-1907-1937-Journey-East-Journey-West-by-Mircea-Eliade.pdf
    • http://unieoooq.linkpc.net/44e34e54e04e04e0/The-Journey-Home-The-Journey-Collection-1-by-Lisa-Bilbrey.pdf
    • http://unieoooq.linkpc.net/34e34e24e54e54e4/The-Craic-A-Journey-Through-Ireland-by-Mark-McCrum.pdf
    • http://unieoooq.linkpc.net/94e64e34e04e7/100-Years-A-Journey-to-End-a-Vicious-Cycle-by-Mark-L-Baynard.pdf
    • http://unieoooq.linkpc.net/14e34e74e94e24e0/The-Fiftieth-Gate-A-Journey-Through-Memory-by-Mark-Raphael-Baker.pdf
    • http://unieoooq.linkpc.net/14e64e14e64e74e8/House-of-Prayer-No-2-A-Writer-s-Journey-Home-by-Mark-Richard.pdf
    • http://unieoooq.linkpc.net/14e04e54e54e64e74e6/Because-of-Him-The-Story-of-Lynn-Ramey-and-Her-Journey-with-the-Almighty-God-by-Mark-K-Vogl.pdf