Malicious PDF — malware analysis report

Static analysis result for SHA-256 00d428acda996836…

MALICIOUS

PDF

16.6 KB Created: 2019-05-01 19:03:11 +01:00 Authoring application: mPDF 5.7
MD5: 4ebcb4bbe13bb98aae709f27e1e14fec SHA-1: a1ad51e53d42b6d6c78c0ef4b49da7a5f38b16cf SHA-256: 00d428acda99683687edca0ad04ff0617d587ae6abceebc386674939b9710a28
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted are currently flagged as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3098095099096/Supernatural-Noir-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/3098098090090/Lovecraft-Unbound-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/1099094095096092/HAUNTED-ASYLUMS-HAUNTED-CEMETERIES-The-creepiest-places-on-earth-haunted-asylums-haunted-cemeteries-haunted-forests-haunted-woods-True-Tales-of-Haunted-Morgues-Haunted-Forests-Book-1-by-James-Pattern.pdf
    • http://loaminoo.linkpc.net/1090095094097096093/Off-Limits-Tales-of-Alien-Sex-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/4098096091098097/Mad-Hatters-and-March-Hares-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2096091094097/The-Dark-New-Ghost-Stories-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2095098095090/Inferno-New-Tales-of-Terror-and-the-Supernatural-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2093091098098093/Black-Thorn-White-Rose-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2095099092091/The-Year-s-Best-Fantasy-First-Annual-Collection-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2095098098091/Silver-Birch-Blood-Moon-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2096096098097/After-Nineteen-Stories-of-Apocalypse-and-Dystopia-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2090092098096095/Black-Swan-White-Raven-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/4098092095093094/Swan-Sister-Fairy-Tales-Retold-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2096091093092/The-Faery-Reel-Tales-from-the-Twilight-Realm-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2090093090098093/Swan-Sister-Fairy-Tales-Retold-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/5093095093090096/The-Year-s-Best-Fantasy-and-Horror-Fifth-Annual-Collection-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2092091096098091/Naked-City-Tales-of-Urban-Fantasy-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2090092098097092/A-Wolf-at-the-Door-And-Other-Retold-Fairy-Tales-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/4094095098090096/The-Year-s-Best-Fantasy-and-Horror-Sixteenth-Annual-Collection-by-Ellen-Datlow.pdf
    • http://loaminoo.linkpc.net/2095099090099/The-Year-s-Best-Fantasy-and-Horror-Fourth-Annual-Collection-by-Ellen-Datlow.pdf