Malicious PDF — malware analysis report

Static analysis result for SHA-256 091b95a7e89a6b34…

MALICIOUS

PDF

16.9 KB Created: 2019-04-30 08:13:43 +01:00 Authoring application: mPDF 5.7
MD5: 87946e570bba56783bd5406f14fccd45 SHA-1: 235da7d99b412e5f531b6b91a5fbbb915bc479eb SHA-256: 091b95a7e89a6b343476a8b538905e4a89e014fe130243f116b15193d69c5b1e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs that form a link farm, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and structure suggest an attempt to manipulate search engine results or distribute content, which is a common tactic for malicious PDFs. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094093092099094/A-Scandalous-Freedom-by-Steve-Brown.pdf
    • http://loaminoo.linkpc.net/3092094094096098/Freedom-s-Dawn-The-Frontiers-Saga-4-by-Ryk-Brown.pdf
    • http://loaminoo.linkpc.net/9099096098091/When-Your-Rope-Breaks-by-Steve-Brown.pdf
    • http://loaminoo.linkpc.net/6098098095095099/The-Belles-of-Charleston-by-Steve-Brown.pdf
    • http://loaminoo.linkpc.net/6098098096092094/The-Charleston-Ripper-by-Steve-Brown.pdf
    • http://loaminoo.linkpc.net/6098098096092095/The-Charleston-Vampire-by-Steve-Brown.pdf
    • http://loaminoo.linkpc.net/2097099094097095/Cletus-An-Historical-Novel-about-Slavery-Freedom-Revenge-and-Redemption-in-Civil-War-Indian-Territory-by-William-Brown.pdf
    • http://loaminoo.linkpc.net/4093090094098097/Scandalous-Scandalous-1-by-Ella-Steele.pdf
    • http://loaminoo.linkpc.net/2092099095099098/A-Scandalous-Wife-Scandalous-1-by-Ava-Stone.pdf
    • http://loaminoo.linkpc.net/4096098098091091/In-Pursuit-of-a-Scandalous-Lady-Scandalous-Lady-1-by-Gayle-Callen.pdf
    • http://loaminoo.linkpc.net/1094095096092093/Hell-Fire-amp-Freedom-Fighting-for-Freedom-1-by-Shannon-Callahan.pdf
    • http://loaminoo.linkpc.net/3093092094097/Freedom-Is-Freedom-Ain-t-Jazz-and-the-Making-of-the-Sixties-by-Scott-Saul.pdf
    • http://loaminoo.linkpc.net/3090097091092/Freedom-Volume-2-Freedom-In-The-Modern-World-by-Orlando-Patterson.pdf
    • http://loaminoo.linkpc.net/3096094097098099/The-Crocodile-Hunter-The-Incredible-Life-and-Adventures-of-Steve-and-Terri-Irwin-by-Steve-Irwin.pdf
    • http://loaminoo.linkpc.net/4099095094096092/Last-Dog-on-the-Hill-The-Unforgettable-Story-of-Lou-Best-Friend-and-Hero-Steve-Duno-by-Steve-Duno.pdf
    • http://loaminoo.linkpc.net/5096095093095/Brown-What-Being-Brown-in-the-World-Today-Means-by-Kamal-Al-Solaylee.pdf
    • http://loaminoo.linkpc.net/1090091095096096/Scandalous-by-ReChella.pdf
    • http://loaminoo.linkpc.net/7095093092094095/Man-Thing-by-Steve-Gerber-The-Complete-Collection-Vol-1-by-Steve-Gerber.pdf
    • http://loaminoo.linkpc.net/6091099092095093/Solitude-And-Freedom-Solitude-And-Freedom-1-by-Toota-Alqallaf.pdf
    • http://loaminoo.linkpc.net/4097090092094090/Scandalous-Liaisons-by-Sylvia-Day.pdf