Malicious PDF — malware analysis report

Static analysis result for SHA-256 056cfdb3c9f4b749…

MALICIOUS

PDF

15.7 KB Created: 2019-05-06 16:36:49 +01:00 Authoring application: mPDF 5.7
MD5: f363ad561afb6b126f41e112c4779ebd SHA-1: 7f4ff5e9ea5b4b40e3e195b93aa5b62a1a3b0f66 SHA-256: 056cfdb3c9f4b749aae5c6e50b6ec4a560413dbbd02b20230ce54627108f859e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, which is a common tactic for SEO manipulation or distributing malicious content. While the specific URLs extracted were flagged as benign, the sheer volume and structure suggest a malicious intent to redirect users. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7092094091092092/Dickie-Brennan-s-Palace-Cafe-The-Flavor-of-New-Orleans-by-Dick-Brennan.pdf
    • http://loaminoo.linkpc.net/5092098095090099/Danny-Dunn-Scientific-Detective-Danny-Dunn-14-by-Jay-Williams.pdf
    • http://loaminoo.linkpc.net/5092098094096092/Danny-Dunn-and-the-Smallifying-Machine-Danny-Dunn-11-by-Jay-Williams.pdf
    • http://loaminoo.linkpc.net/1094097095096097/Danny-Dunn-and-the-Homework-Machine-Danny-Dunn-3-by-Jay-Williams.pdf
    • http://loaminoo.linkpc.net/5092098095090096/Danny-Dunn-and-the-Heat-Ray-Danny-Dunn-7-by-Jay-Williams.pdf
    • http://loaminoo.linkpc.net/9097090096098094/Blueprint-for-a-Battlestar-by-Rod-Pyle.pdf
    • http://loaminoo.linkpc.net/9097090096097099/A-Blueprint-for-Love-by-Chatura-Rao.pdf
    • http://loaminoo.linkpc.net/9097090098092090/The-Human-Blueprint-by-Robert-Shapiro.pdf
    • http://loaminoo.linkpc.net/9097090096090093/The-Secret-Millionaire-Blueprint-by-Arfeen-Khan.pdf
    • http://loaminoo.linkpc.net/9097090095095097/The-Making-of-Adventures-In-Counter-Culture-by-Blueprint.pdf
    • http://loaminoo.linkpc.net/3094090098095096/The-Not-So-Big-House-A-Blueprint-for-the-Way-We-Really-Live-by-Sarah-Susanka.pdf
    • http://loaminoo.linkpc.net/7090090094097094/Falling-For-Ken-Blueprint-to-Love-2-by-Lauren-Giordano.pdf
    • http://loaminoo.linkpc.net/9097090098092091/Blueprint-for-a-Green-Economy-by-David-W-Pearce.pdf
    • http://loaminoo.linkpc.net/9097090098091093/The-Blueprint-Averting-Global-Collapse-by-Daniel-Rirdan.pdf
    • http://loaminoo.linkpc.net/7090090094097096/Chasing-Marisol-Blueprint-to-Love-3-by-Lauren-Giordano.pdf
    • http://loaminoo.linkpc.net/1091093094097096098/The-Ever-Blooming-Flower-Garden-A-Blueprint-for-Continuous-Color-by-Lee-Schneller.pdf
    • http://loaminoo.linkpc.net/9097090096090091/The-Black-Male-Handbook-A-Blueprint-for-Life-by-Kevin-Powell.pdf
    • http://loaminoo.linkpc.net/2099091097096095/Anger-Guide-A-Blueprint-for-Twelve-Structured-Sessions-by-Claudia-Black.pdf
    • http://loaminoo.linkpc.net/1091093097095099099/A-New-Common-Sense-Being-A-Blueprint-For-We-The-People-To-Reclaim-Our-Democracy-by-Thomas-Gallier.pdf
    • http://loaminoo.linkpc.net/5096098090096090/Blueprint-for-Writing-A-Writer-s-Guide-To-Creativity-Craft-amp-Career-by-Rachel-Ballon.pdf