Malicious PDF — malware analysis report

Static analysis result for SHA-256 08a3a8fdceb5ec81…

MALICIOUS

PDF

19.2 KB Created: 2019-05-02 10:39:34 +01:00 Authoring application: mPDF 5.7
MD5: 47f08d218861ca65cfe2e2576d0be215 SHA-1: 4e0824e513c847f0832362ebf8cb6ba662dedc0f SHA-256: 08a3a8fdceb5ec81c105cd62e587fed406a9ec8bb1a0df02574271a09bef185d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample was flagged by a machine learning classifier and contains a large number of embedded URLs pointing to external PDF files. The document body, though heavily obfuscated, contains these URLs, suggesting the primary purpose is to act as a link farm. This technique is often used for SEO manipulation or to distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4091097099097092/Africa-on-Six-Wheels-A-Semester-on-Safari-by-Betty-Levitov.pdf
    • http://loaminoo.linkpc.net/1090097090096093090/Southern-Africa-Safari-Companion-by-Diana-Lerche.pdf
    • http://loaminoo.linkpc.net/4090098090096096/The-Marginal-Safari-Scouting-the-Edge-of-South-Africa-by-Justin-Fox.pdf
    • http://loaminoo.linkpc.net/5094090091094099/China-Safari-On-the-Trail-of-Beijing-s-Expansion-in-Africa-by-Serge-Michel.pdf
    • http://loaminoo.linkpc.net/3093093093098091/Secret-Warriors-Volume-6-Wheels-Within-Wheels-by-Jonathan-Hickman.pdf
    • http://loaminoo.linkpc.net/2091091093096090/Wheels-of-Steel-Book-3-Wheels-of-Steel-3-by-Pepper-Pace.pdf
    • http://loaminoo.linkpc.net/2091091093095099/Wheels-of-Steel-Book-1-Wheels-of-Steel-1-by-Pepper-Pace.pdf
    • http://loaminoo.linkpc.net/2097092098098098/Semester-Aboard-More-than-Magic-1-by-Elizabeth-Kirke.pdf
    • http://loaminoo.linkpc.net/3095097096096094/Betty-and-Friends-My-Life-at-the-Zoo-by-Betty-White.pdf
    • http://loaminoo.linkpc.net/1090095092093096097/Betty-and-the-Beast-Betty-and-Veronica-265-by-Dan-Parent.pdf
    • http://loaminoo.linkpc.net/6090094096094090/ME1510-Radar-Imaging-Principles-Contents-for-One-Semester-by-Dreamcatcher.pdf
    • http://loaminoo.linkpc.net/6090094096093091/ME1300-Antenna-and-Propagation-Teaching-Slides-Contents-for-One-Semester-by-Dreamcatcher.pdf
    • http://loaminoo.linkpc.net/6090094096093094/ME1120-400-Mobile-Communications-Teaching-Slides-Contents-for-One-Semester-by-Dreamcatcher.pdf
    • http://loaminoo.linkpc.net/6090094096093095/ME3200-Electronic-Instrumentation-and-Measurement-Teaching-Slides-Contents-for-One-Semester-by-Dreamcatcher.pdf
    • http://loaminoo.linkpc.net/3091091094099091/Betty-Crocker-Ultimate-Cake-Mix-Cookbook-Create-Sweet-Magic-from-a-Mix-by-Betty-Crocker.pdf
    • http://loaminoo.linkpc.net/8099092092092099/Einfuhrung-in-Die-Programmiersprache-FORTRAN-IV-Anleitung-Zum-Selbstudium-Skriptum-Fur-Horer-Aller-Fachrichtungen-AB-1-Semester-by-Gunther-Lamprecht.pdf
    • http://loaminoo.linkpc.net/4092091099097093/Safari-for-the-Soul-by-Jan-Boal.pdf
    • http://loaminoo.linkpc.net/1090098090092094091/Einfuhrung-in-Das-Wissenschaftliche-Arbeiten-Bibliographie-Dokumentation-Manuskript-Lehrbuch-Fur-Studenten-Aller-Fachrichtungen-AB-1-Semester-by-Helmut-Seiffert.pdf
    • http://loaminoo.linkpc.net/3096092091093090/Blood-Safari-by-Deon-Meyer.pdf
    • http://loaminoo.linkpc.net/1093092096096095/Poverty-Safari-by-Darren-McGarvey.pdf